2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5019 | — | — | 8.0% | Oct 3, 2016 | CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2... |
| CVE-2016-1372 | — | — | 1.6% | Oct 3, 2016 | ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a... |
| CVE-2016-1371 | — | — | 1.6% | Oct 3, 2016 | ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a... |
| CVE-2016-1244 | — | — | 5.3% | Oct 3, 2016 | The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a direct... |
| CVE-2016-1243 | — | — | 5.0% | Oct 3, 2016 | Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a... |
| CVE-2016-7445 | — | — | 4.2% | Oct 3, 2016 | convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and ap... |
| CVE-2016-7442 | — | — | 0.5% | Oct 3, 2016 | The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive p... |
| CVE-2016-7397 | — | — | 0.5% | Oct 3, 2016 | The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive p... |
| CVE-2016-5700 | — | — | 6.4% | Oct 3, 2016 | Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 1... |
| CVE-2016-3658 | — | — | 4.0% | Oct 3, 2016 | The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allo... |
| CVE-2016-3634 | — | — | 1.7% | Oct 3, 2016 | The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to c... |
| CVE-2016-3633 | — | — | 1.6% | Oct 3, 2016 | The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of serv... |
| CVE-2016-3631 | — | — | 2.6% | Oct 3, 2016 | The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to ... |
| CVE-2016-3625 | — | — | 1.8% | Oct 3, 2016 | tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of... |
| CVE-2016-3624 | — | — | 4.1% | Oct 3, 2016 | The cvtClump function in the rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of se... |
| CVE-2016-3623 | — | — | 5.5% | Oct 3, 2016 | The rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero) by... |
| CVE-2016-3622 | — | — | 3.9% | Oct 3, 2016 | The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause ... |
| CVE-2016-3621 | — | — | 2.1% | Oct 3, 2016 | The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used,... |
| CVE-2016-3620 | — | — | 3.2% | Oct 3, 2016 | The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used,... |
| CVE-2016-3619 | — | — | 2.3% | Oct 3, 2016 | The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" opti... |
| CVE-2016-4436 | — | — | 6.8% | Oct 3, 2016 | Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to i... |
| CVE-2016-1240 | — | — | 9.8% | Oct 3, 2016 | The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia... |
| CVE-2016-5995 | — | — | 0.4% | Oct 1, 2016 | Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux... |
| CVE-2016-5986 | — | — | 2.4% | Oct 1, 2016 | IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9... |
| CVE-2016-3042 | — | — | 1.1% | Oct 1, 2016 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now