2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4330 | — | — | 0.8% | Nov 18, 2016 | In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the ... |
| CVE-2016-9376 | — | — | 1.6% | Nov 17, 2016 | In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by ... |
| CVE-2016-9375 | — | — | 1.6% | Nov 17, 2016 | In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network t... |
| CVE-2016-9374 | — | — | 1.6% | Nov 17, 2016 | In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by ... |
| CVE-2016-9373 | — | — | 1.7% | Nov 17, 2016 | In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by net... |
| CVE-2016-9372 | — | — | 2.1% | Nov 17, 2016 | In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a captur... |
| CVE-2016-7917 | — | — | 1.5% | Nov 16, 2016 | The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a ba... |
| CVE-2016-7916 | — | — | 0.4% | Nov 16, 2016 | Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obt... |
| CVE-2016-7915 | — | — | 1.7% | Nov 16, 2016 | The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attack... |
| CVE-2016-7914 | — | — | 2.0% | Nov 16, 2016 | The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check ... |
| CVE-2016-7913 | HIGH | 7.8 | 2.2% | Nov 16, 2016 | The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users ... |
| CVE-2016-7912 | HIGH | 7.8 | 2.1% | Nov 16, 2016 | Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux ker... |
| CVE-2016-7911 | HIGH | 7.8 | 1.5% | Nov 16, 2016 | Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel before 4.6.6 allows local users to ... |
| CVE-2016-7910 | HIGH | 7.8 | 3.0% | Nov 16, 2016 | Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows loc... |
| CVE-2016-9318 | MEDIUM | 5.5 | 2.9% | Nov 16, 2016 | libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indic... |
| CVE-2016-7165 | — | — | 0.4% | Nov 15, 2016 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (... |
| CVE-2016-5763 | — | — | 1.6% | Nov 15, 2016 | Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Sc... |
| CVE-2016-0909 | — | — | 0.4% | Nov 15, 2016 | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may exp... |
| CVE-2016-8661 | — | — | 0.4% | Nov 15, 2016 | Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited whic... |
| CVE-2016-9287 | — | — | 1.5% | Nov 15, 2016 | In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passe... |
| CVE-2016-8908 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated... |
| CVE-2016-8907 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authentic... |
| CVE-2016-8906 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticate... |
| CVE-2016-8905 | — | — | 2.0% | Nov 14, 2016 | SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to exec... |
| CVE-2016-8904 | — | — | 1.9% | Nov 14, 2016 | SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authent... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now