2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2936——IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obt...
CVE-2016-2935——The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service vi...
CVE-2016-2934——Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arb...
CVE-2016-2933——Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators t...
CVE-2016-2932——IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.
CVE-2016-2931——IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the...
CVE-2016-9481——In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into sh...
CVE-2016-9480——libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by u...
CVE-2016-8224——A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrativ...
CVE-2016-8223——During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interf...
CVE-2016-1251——There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQ...
CVE-2016-1247HIGH7.8The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS...
CVE-2016-5685——Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access throu...
CVE-2016-5765——Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) ...
CVE-2016-5393——In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode ca...
CVE-2016-9644——The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extende...
CVE-2016-9555CRITICAL9.8The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for th...
CVE-2016-9313HIGH7.8security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with...
CVE-2016-9191——The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows l...
CVE-2016-9178——The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a cer...
CVE-2016-9084——drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local us...
CVE-2016-9083HIGH7.8drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and...
CVE-2016-8650——The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated f...
CVE-2016-8646——The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of...
CVE-2016-8645——The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now