2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6307 | — | — | 13.8% | Sep 26, 2016 | The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length... |
| CVE-2016-6305 | — | — | 16.0% | Sep 26, 2016 | The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a ... |
| CVE-2016-6980 | — | — | 5.6% | Sep 26, 2016 | Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspe... |
| CVE-2016-6038 | — | — | 1.7% | Sep 26, 2016 | Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3... |
| CVE-2016-6913 | — | — | 0.9% | Sep 26, 2016 | Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to in... |
| CVE-2016-6901 | — | — | 1.0% | Sep 26, 2016 | Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR36... |
| CVE-2016-6827 | — | — | 1.0% | Sep 26, 2016 | Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated use... |
| CVE-2016-6826 | — | — | 0.7% | Sep 26, 2016 | Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a craft... |
| CVE-2016-6172 | — | — | 3.9% | Sep 26, 2016 | PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (me... |
| CVE-2016-6153 | — | — | 0.5% | Sep 26, 2016 | os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow loca... |
| CVE-2016-6142 | — | — | 2.9% | Sep 26, 2016 | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYS... |
| CVE-2016-4972 | — | — | 3.2% | Sep 26, 2016 | OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x b... |
| CVE-2016-3639 | — | — | 1.5% | Sep 26, 2016 | SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified H... |
| CVE-2016-7142 | — | — | 1.1% | Sep 26, 2016 | The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows... |
| CVE-2016-6518 | — | — | 1.1% | Sep 26, 2016 | Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a de... |
| CVE-2016-5746 | — | — | 0.5% | Sep 26, 2016 | libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary fi... |
| CVE-2016-8279 | — | — | 0.6% | Sep 26, 2016 | The video driver in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B362, CRR-UL20 before CRR-UL20C00... |
| CVE-2016-7098 | — | — | 7.5% | Sep 26, 2016 | Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow... |
| CVE-2016-6840 | — | — | 0.9% | Sep 26, 2016 | Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 al... |
| CVE-2016-6276 | — | — | 0.3% | Sep 26, 2016 | Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain ro... |
| CVE-2016-5406 | — | — | 2.9% | Sep 26, 2016 | The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticate... |
| CVE-2016-5395 | — | — | 2.1% | Sep 26, 2016 | Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger befo... |
| CVE-2016-4993 | — | — | 2.6% | Sep 26, 2016 | CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Applicati... |
| CVE-2016-3110 | — | — | 3.6% | Sep 26, 2016 | mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http ... |
| CVE-2016-5997 | — | — | 0.8% | Sep 26, 2016 | The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 bef... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now