2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6892 | — | — | 1.9% | Jan 5, 2017 | The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of ... |
| CVE-2016-6891 | — | — | 1.9% | Jan 5, 2017 | MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit... |
| CVE-2016-6890 | — | — | 6.4% | Jan 5, 2017 | Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Sub... |
| CVE-2016-9754 | HIGH | 7.8 | 0.5% | Jan 5, 2017 | The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.... |
| CVE-2016-10030 | — | — | 2.5% | Jan 5, 2017 | The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 h... |
| CVE-2016-7169 | — | — | 3.2% | Jan 5, 2017 | Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php ... |
| CVE-2016-7168 | — | — | 2.8% | Jan 5, 2017 | Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress... |
| CVE-2016-10012 | HIGH | 7.8 | 1.3% | Jan 5, 2017 | The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure... |
| CVE-2016-10011 | MEDIUM | 6.2 | 1.1% | Jan 5, 2017 | authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which mig... |
| CVE-2016-10010 | HIGH | 7 | 4.2% | Jan 5, 2017 | sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which ... |
| CVE-2016-10009 | HIGH | 7.3 | 37.4% | Jan 5, 2017 | Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute... |
| CVE-2016-7903 | — | — | 1.1% | Jan 4, 2017 | Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to m... |
| CVE-2016-7902 | — | — | 3.0% | Jan 4, 2017 | Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authentica... |
| CVE-2016-7399 | — | — | 4.9% | Jan 4, 2017 | scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3,... |
| CVE-2016-6894 | — | — | 1.7% | Jan 4, 2017 | Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote att... |
| CVE-2016-9936 | — | — | 4.3% | Jan 4, 2017 | The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial ... |
| CVE-2016-9935 | — | — | 7.0% | Jan 4, 2017 | The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers... |
| CVE-2016-9934 | — | — | 6.8% | Jan 4, 2017 | ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2016-9933 | — | — | 6.9% | Jan 4, 2017 | Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) befor... |
| CVE-2016-9138 | — | — | 3.8% | Jan 4, 2017 | PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remo... |
| CVE-2016-9137 | — | — | 5.3% | Jan 4, 2017 | Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before ... |
| CVE-2016-8860 | — | — | 1.9% | Jan 4, 2017 | Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data ... |
| CVE-2016-8670 | — | — | 4.7% | Jan 4, 2017 | Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.... |
| CVE-2016-6595 | — | — | 2.5% | Jan 4, 2017 | The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of clu... |
| CVE-2016-10116 | — | — | 4.1% | Jan 4, 2017 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, an... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now