2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-2383MEDIUM5.5The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the ...
CVE-2016-0668MEDIUM4.1Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 an...
CVE-2016-0651MEDIUM5.5Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors relat...
CVE-2016-0642MEDIUM4.7Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local us...
CVE-2016-0162MEDIUM4.3Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScr...
CVE-2016-0128MEDIUM6.8The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 ...
CVE-2016-1180MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x al...
CVE-2016-3975MEDIUM6.1Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbi...
CVE-2016-3973MEDIUM5.3The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allo...
CVE-2016-2858MEDIUM6.5QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a...
CVE-2016-2292MEDIUM6.5Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05...
CVE-2016-2291MEDIUM6.5Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.0...
CVE-2016-1160MEDIUM6.1Cross-site scripting (XSS) vulnerability in the WP Favorite Posts plugin before 1.6.6 for WordPress allows remote attack...
CVE-2016-3115MEDIUM6.4Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to...
CVE-2016-2075MEDIUM5.4Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux a...
CVE-2016-0821MEDIUM5.5The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-0...
CVE-2016-1285MEDIUM6.8named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fe...
CVE-2016-2774MEDIUM5.9ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessio...
CVE-2016-0702MEDIUM5.1The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g...
CVE-2016-2279MEDIUM6.1Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef...
CVE-2016-2388MEDIUM5.3The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor...
CVE-2016-0753MEDIUM5.3Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use...
CVE-2016-0747MEDIUM5.3The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote...
CVE-2016-2073MEDIUM6.5The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bound...
CVE-2016-1144MEDIUM5.4Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now