2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6910The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung ...
CVE-2016-9889Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 L...
CVE-2016-9561The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a den...
CVE-2016-9154Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PX...
CVE-2016-8595The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of se...
CVE-2016-7905The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of s...
CVE-2016-7785The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of s...
CVE-2016-7562The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial o...
CVE-2016-7555The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding a...
CVE-2016-7502The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memo...
CVE-2016-7450The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory...
CVE-2016-7122The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decode...
CVE-2016-6881The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loo...
CVE-2016-6671The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of servi...
CVE-2016-6659Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh ...
CVE-2016-7954Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name coll...
CVE-2016-9675HIGH7.8openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause th...
CVE-2016-9181perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an ...
CVE-2016-9180perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig do...
CVE-2016-9179lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends wit...
CVE-2016-7091sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux impleme...
CVE-2016-7172NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user...
CVE-2016-5851HIGH8.8python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted d...
CVE-2016-2349Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via...
CVE-2016-5103Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4552. Reason: This candidate is a reservation ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now