2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4331——When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that...
CVE-2016-4330——In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the ...
CVE-2016-9376——In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by ...
CVE-2016-9375——In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network t...
CVE-2016-9374——In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by ...
CVE-2016-9373——In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by net...
CVE-2016-9372——In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a captur...
CVE-2016-7917——The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a ba...
CVE-2016-7916——Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obt...
CVE-2016-7915——The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attack...
CVE-2016-7914——The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check ...
CVE-2016-7913HIGH7.8The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users ...
CVE-2016-7912HIGH7.8Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux ker...
CVE-2016-7911HIGH7.8Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel before 4.6.6 allows local users to ...
CVE-2016-7910HIGH7.8Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows loc...
CVE-2016-9318MEDIUM5.5libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indic...
CVE-2016-7165——A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (...
CVE-2016-5763——Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Sc...
CVE-2016-0909——EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may exp...
CVE-2016-8661——Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited whic...
CVE-2016-9287——In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passe...
CVE-2016-8908——SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated...
CVE-2016-8907——SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authentic...
CVE-2016-8906——SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticate...
CVE-2016-8905——SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to exec...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now