2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6833 | MEDIUM | 4.4 | 0.4% | Dec 10, 2016 | Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allo... |
| CVE-2016-6490 | MEDIUM | 4.4 | 0.4% | Dec 10, 2016 | The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators ... |
| CVE-2016-4964 | MEDIUM | 6 | 0.4% | Dec 10, 2016 | The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators... |
| CVE-2016-5424 | — | — | 4.7% | Dec 9, 2016 | PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might all... |
| CVE-2016-5423 | — | — | 6.0% | Dec 9, 2016 | PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow rem... |
| CVE-2016-9106 | MEDIUM | 6 | 0.4% | Dec 9, 2016 | Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators... |
| CVE-2016-9105 | MEDIUM | 6 | 0.4% | Dec 9, 2016 | Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators ... |
| CVE-2016-9104 | MEDIUM | 4.4 | 0.4% | Dec 9, 2016 | Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Qu... |
| CVE-2016-9103 | MEDIUM | 6 | 0.4% | Dec 9, 2016 | The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtai... |
| CVE-2016-9102 | MEDIUM | 6 | 0.4% | Dec 9, 2016 | Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administ... |
| CVE-2016-9101 | MEDIUM | 6 | 0.4% | Dec 9, 2016 | Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of ... |
| CVE-2016-6501 | — | — | 3.8% | Dec 9, 2016 | JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted ser... |
| CVE-2016-6496 | — | — | 4.7% | Dec 9, 2016 | The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute a... |
| CVE-2016-6321 | HIGH | 7.5 | 15.2% | Dec 9, 2016 | Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote atta... |
| CVE-2016-9014 | — | — | 6.1% | Dec 9, 2016 | Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow rem... |
| CVE-2016-9013 | — | — | 5.1% | Dec 9, 2016 | Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary datab... |
| CVE-2016-6829 | CRITICAL | 9.8 | 2.4% | Dec 9, 2016 | The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove an... |
| CVE-2016-6523 | — | — | 1.3% | Dec 9, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers ... |
| CVE-2016-6301 | HIGH | 7.5 | 8.9% | Dec 9, 2016 | The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of se... |
| CVE-2016-8858 | HIGH | 7.5 | 29.5% | Dec 9, 2016 | The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of ... |
| CVE-2016-9120 | HIGH | 7.8 | 1.7% | Dec 8, 2016 | Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows loca... |
| CVE-2016-9920 | — | — | 5.6% | Dec 8, 2016 | steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the send... |
| CVE-2016-9919 | HIGH | 7.5 | 5.7% | Dec 8, 2016 | The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data stru... |
| CVE-2016-8104 | — | — | 0.3% | Dec 8, 2016 | Buffer overflow in Intel PROSet/Wireless Software and Drivers in versions before 19.20.3 allows a local user to crash if... |
| CVE-2016-8103 | — | — | 0.3% | Dec 8, 2016 | SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now