2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10072 | MEDIUM | 5.3 | 0.5% | Dec 27, 2016 | WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potent... |
| CVE-2016-10031 | — | — | 1.1% | Dec 27, 2016 | WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS... |
| CVE-2016-9224 | — | — | 1.4% | Dec 26, 2016 | A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections... |
| CVE-2016-9223 | — | — | 2.9% | Dec 26, 2016 | A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow a... |
| CVE-2016-9217 | — | — | 1.3% | Dec 26, 2016 | A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthe... |
| CVE-2016-9681 | — | — | 1.3% | Dec 25, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inje... |
| CVE-2016-10041 | — | — | 1.1% | Dec 25, 2016 | An issue was discovered in Sprecher Automation SPRECON-E Service Program before 3.43 SP0. Under certain preconditions, i... |
| CVE-2016-10006 | MEDIUM | 6.1 | 2.0% | Dec 24, 2016 | In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content),... |
| CVE-2016-10039 | HIGH | 7.3 | 1.8% | Dec 24, 2016 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local... |
| CVE-2016-10038 | — | — | 1.9% | Dec 24, 2016 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local... |
| CVE-2016-10037 | HIGH | 7.3 | 1.8% | Dec 24, 2016 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local... |
| CVE-2016-9923 | MEDIUM | 5.5 | 1.2% | Dec 23, 2016 | Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur w... |
| CVE-2016-9921 | MEDIUM | 6.5 | 0.4% | Dec 23, 2016 | Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It c... |
| CVE-2016-9912 | MEDIUM | 6.5 | 0.4% | Dec 23, 2016 | Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It coul... |
| CVE-2016-9911 | MEDIUM | 6.5 | 0.4% | Dec 23, 2016 | Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur ... |
| CVE-2016-9908 | LOW | 3.3 | 0.4% | Dec 23, 2016 | Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. I... |
| CVE-2016-9907 | MEDIUM | 6.5 | 0.4% | Dec 23, 2016 | Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could o... |
| CVE-2016-9037 | HIGH | 7.5 | 3.7% | Dec 23, 2016 | An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g... |
| CVE-2016-9036 | HIGH | 7.5 | 2.8% | Dec 23, 2016 | An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3... |
| CVE-2016-8707 | HIGH | 7.8 | 3.7% | Dec 23, 2016 | An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A... |
| CVE-2016-7968 | — | — | 1.2% | Dec 23, 2016 | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not saniti... |
| CVE-2016-7967 | — | — | 1.9% | Dec 23, 2016 | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is execut... |
| CVE-2016-7966 | — | — | 2.3% | Dec 23, 2016 | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer... |
| CVE-2016-7787 | — | — | 1.7% | Dec 23, 2016 | A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually ... |
| CVE-2016-2312 | — | — | 0.4% | Dec 23, 2016 | Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen be... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now