2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-2065HIGH7.8sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualc...
CVE-2016-2064HIGH7.8sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualc...
CVE-2016-2063HIGH7.8Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal...
CVE-2016-4029HIGH8.6WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, wh...
CVE-2016-6128HIGH7.5The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP befor...
CVE-2016-6187HIGH7.8The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff...
CVE-2016-3841HIGH7.3The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or ...
CVE-2016-6185HIGH7.8The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which mig...
CVE-2016-1238HIGH7.8(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scrip...
CVE-2016-1461HIGH7.5Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware dete...
CVE-2016-5131HIGH8.8Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attac...
CVE-2016-3565HIGH7.6Unspecified vulnerability in the Oracle Retail Order Broker component in Oracle Retail Applications 5.1 and 5.2 allows r...
CVE-2016-3471HIGH7.5Unspecified vulnerability in Oracle MySQL 5.5.45 and earlier and 5.6.26 and earlier allows local users to affect confide...
CVE-2016-5387HIGH8.1The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from t...
CVE-2016-5386HIGH8.1The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and there...
CVE-2016-5385HIGH8.1PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect...
CVE-2016-5790HIGH7.5Tollgrade LightHouse SMS before 5.1 patch 3 allows remote attackers to bypass authentication and restart the software vi...
CVE-2016-4529HIGH7.3An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers befor...
CVE-2016-4249HIGH8.8Heap-based buffer overflow in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows an...
CVE-2016-4248HIGH8.8Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows ...
CVE-2016-4246HIGH8.8Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632...
CVE-2016-4245HIGH8.8Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632...
CVE-2016-4244HIGH8.8Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632...
CVE-2016-4243HIGH8.8Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632...
CVE-2016-4242HIGH8.8Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now