2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7916 | — | — | 0.4% | Nov 16, 2016 | Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obt... |
| CVE-2016-7915 | — | — | 1.7% | Nov 16, 2016 | The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attack... |
| CVE-2016-7914 | — | — | 2.0% | Nov 16, 2016 | The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check ... |
| CVE-2016-7165 | — | — | 0.4% | Nov 15, 2016 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (... |
| CVE-2016-5763 | — | — | 1.6% | Nov 15, 2016 | Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Sc... |
| CVE-2016-0909 | — | — | 0.4% | Nov 15, 2016 | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may exp... |
| CVE-2016-8661 | — | — | 0.4% | Nov 15, 2016 | Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited whic... |
| CVE-2016-9287 | — | — | 1.5% | Nov 15, 2016 | In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passe... |
| CVE-2016-8908 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated... |
| CVE-2016-8907 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authentic... |
| CVE-2016-8906 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticate... |
| CVE-2016-8905 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to exec... |
| CVE-2016-8904 | — | — | 1.9% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authent... |
| CVE-2016-8903 | — | — | 1.9% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenti... |
| CVE-2016-8902 | — | — | 2.8% | Nov 14, 2016 | SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated atta... |
| CVE-2016-9296 | — | — | 7.0% | Nov 12, 2016 | A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the va... |
| CVE-2016-9288 | — | — | 1.5% | Nov 11, 2016 | In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "tar... |
| CVE-2016-9286 | — | — | 1.5% | Nov 11, 2016 | framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access t... |
| CVE-2016-9285 | — | — | 1.5% | Nov 11, 2016 | framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read u... |
| CVE-2016-9284 | — | — | 1.5% | Nov 11, 2016 | getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers... |
| CVE-2016-9283 | — | — | 1.7% | Nov 11, 2016 | SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database... |
| CVE-2016-9282 | — | — | 1.7% | Nov 11, 2016 | SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attacker... |
| CVE-2016-9277 | — | — | 1.4% | Nov 11, 2016 | Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of ser... |
| CVE-2016-9272 | — | — | 2.2% | Nov 11, 2016 | A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site dat... |
| CVE-2016-9268 | — | — | 5.0% | Nov 10, 2016 | Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear th... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now