2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8903SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenti...
CVE-2016-8902SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated atta...
CVE-2016-9296A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the va...
CVE-2016-9294HIGH7.5Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduc...
CVE-2016-9288In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "tar...
CVE-2016-9286framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access t...
CVE-2016-9285framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read u...
CVE-2016-9284getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers...
CVE-2016-9283SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database...
CVE-2016-9282SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attacker...
CVE-2016-9277Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of ser...
CVE-2016-9274HIGH7.8Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git....
CVE-2016-9272A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site dat...
CVE-2016-5195HIGH7Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev...
CVE-2016-9268Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear th...
CVE-2016-7148MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, ...
CVE-2016-7146MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted ...
CVE-2016-7490The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A...
CVE-2016-7489Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp ...
CVE-2016-7488Teradata Virtual Machine Community Edition v15.10 has insecure file permissions on /etc/luminex/pkgmgr. These could allo...
CVE-2016-4095Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acro...
CVE-2016-7256HIGH8.8atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...
CVE-2016-7255HIGH7.8The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, ...
CVE-2016-7254Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remo...
CVE-2016-7253The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.d...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now