2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6644 | — | — | 1.9% | Sep 17, 2016 | EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase document... |
| CVE-2016-1482 | — | — | 4.0% | Sep 17, 2016 | Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into a... |
| CVE-2016-6938 | — | — | 8.7% | Sep 17, 2016 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15... |
| CVE-2016-6937 | — | — | 6.6% | Sep 17, 2016 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro... |
| CVE-2016-6407 | — | — | 2.5% | Sep 17, 2016 | Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of ser... |
| CVE-2016-6401 | — | — | 0.8% | Sep 17, 2016 | Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, all... |
| CVE-2016-5843 | — | — | 3.2% | Sep 17, 2016 | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Op... |
| CVE-2016-7420 | — | — | 2.3% | Sep 16, 2016 | Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling t... |
| CVE-2016-6936 | — | — | 3.8% | Sep 16, 2016 | Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, whi... |
| CVE-2016-6302 | — | — | 26.4% | Sep 16, 2016 | The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validatio... |
| CVE-2016-4263 | — | — | 5.8% | Sep 16, 2016 | Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspe... |
| CVE-2016-4262 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4261 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4260 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4259 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4258 | — | — | 5.0% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4257 | — | — | 5.0% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4256 | — | — | 5.0% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-2182 | — | — | 44.2% | Sep 16, 2016 | The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, whic... |
| CVE-2016-2181 | — | — | 22.6% | Sep 16, 2016 | The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in... |
| CVE-2016-2179 | — | — | 26.6% | Sep 16, 2016 | The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with... |
| CVE-2016-3381 | — | — | 15.0% | Sep 14, 2016 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, ... |
| CVE-2016-3379 | — | — | 8.2% | Sep 14, 2016 | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attac... |
| CVE-2016-3378 | — | — | 15.3% | Sep 14, 2016 | Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13,... |
| CVE-2016-3377 | — | — | 16.2% | Sep 14, 2016 | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now