2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6447 | — | — | 3.1% | Nov 3, 2016 | A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbit... |
| CVE-2016-6441 | — | — | 4.9% | Nov 3, 2016 | A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated,... |
| CVE-2016-6430 | — | — | 0.3% | Nov 3, 2016 | A vulnerability in the command-line interface of the Cisco IP Interoperability and Collaboration System (IPICS) could al... |
| CVE-2016-6429 | — | — | 0.8% | Nov 3, 2016 | A vulnerability in the web framework code of the Cisco IP Interoperability and Collaboration System (IPICS) could allow ... |
| CVE-2016-9135 | — | — | 1.8% | Nov 3, 2016 | Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php... |
| CVE-2016-9134 | — | — | 2.0% | Nov 3, 2016 | Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impa... |
| CVE-2016-9086 | — | — | 5.4% | Nov 3, 2016 | GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added... |
| CVE-2016-7453 | — | — | 1.5% | Nov 3, 2016 | The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection. |
| CVE-2016-7452 | — | — | 1.7% | Nov 3, 2016 | The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder ... |
| CVE-2016-7402 | — | — | 1.1% | Nov 3, 2016 | SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges ... |
| CVE-2016-7160 | — | — | 1.1% | Nov 3, 2016 | A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly r... |
| CVE-2016-7095 | — | — | 2.3% | Nov 3, 2016 | Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the ... |
| CVE-2016-4025 | — | — | 0.4% | Nov 3, 2016 | Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x... |
| CVE-2016-8203 | — | — | 1.8% | Oct 31, 2016 | A memory corruption in the IPsec code path of Brocade NetIron OS on Brocade MLXs 5.8.00 through 5.8.00e, 5.9.00 through ... |
| CVE-2016-8879 | — | — | 1.3% | Oct 31, 2016 | The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows ... |
| CVE-2016-8878 | — | — | 2.6% | Oct 31, 2016 | Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, a... |
| CVE-2016-8877 | — | — | 2.9% | Oct 31, 2016 | Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows rem... |
| CVE-2016-8876 | — | — | 2.2% | Oct 31, 2016 | Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, a... |
| CVE-2016-8875 | — | — | 1.1% | Oct 31, 2016 | The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows rem... |
| CVE-2016-8856 | — | — | 0.8% | Oct 31, 2016 | Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerabil... |
| CVE-2016-7991 | — | — | 0.5% | Oct 31, 2016 | On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages res... |
| CVE-2016-7990 | — | — | 2.1% | Oct 31, 2016 | On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP mess... |
| CVE-2016-7989 | — | — | 0.6% | Oct 31, 2016 | On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers... |
| CVE-2016-7988 | — | — | 0.6% | Oct 31, 2016 | On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the co... |
| CVE-2016-7965 | — | — | 1.2% | Oct 31, 2016 | DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now