2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-7916Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obt...
CVE-2016-7915The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attack...
CVE-2016-7914The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check ...
CVE-2016-7165A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (...
CVE-2016-5763Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Sc...
CVE-2016-0909EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may exp...
CVE-2016-8661Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited whic...
CVE-2016-9287In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passe...
CVE-2016-8908SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated...
CVE-2016-8907SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authentic...
CVE-2016-8906SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticate...
CVE-2016-8905SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to exec...
CVE-2016-8904SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authent...
CVE-2016-8903SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenti...
CVE-2016-8902SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated atta...
CVE-2016-9296A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the va...
CVE-2016-9288In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "tar...
CVE-2016-9286framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access t...
CVE-2016-9285framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read u...
CVE-2016-9284getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers...
CVE-2016-9283SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database...
CVE-2016-9282SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attacker...
CVE-2016-9277Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of ser...
CVE-2016-9272A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site dat...
CVE-2016-9268Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear th...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now