2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6371 | — | — | 4.8% | Sep 12, 2016 | Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(... |
| CVE-2016-6370 | — | — | 2.4% | Sep 12, 2016 | Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(... |
| CVE-2016-5954 | — | — | 1.3% | Sep 12, 2016 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8... |
| CVE-2016-5927 | — | — | 0.3% | Sep 12, 2016 | IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x ... |
| CVE-2016-4852 | — | — | 1.7% | Sep 12, 2016 | YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing f... |
| CVE-2016-0331 | — | — | 0.8% | Sep 12, 2016 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Co... |
| CVE-2016-7134 | — | — | 4.8% | Sep 12, 2016 | ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attac... |
| CVE-2016-7133 | — | — | 4.1% | Sep 12, 2016 | Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allo... |
| CVE-2016-7130 | — | — | 6.7% | Sep 12, 2016 | The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers ... |
| CVE-2016-7129 | — | — | 6.8% | Sep 12, 2016 | The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers... |
| CVE-2016-7128 | — | — | 7.8% | Sep 12, 2016 | The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case ... |
| CVE-2016-7127 | — | — | 6.8% | Sep 12, 2016 | The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamm... |
| CVE-2016-7125 | — | — | 5.8% | Sep 12, 2016 | ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers inco... |
| CVE-2016-7124 | — | — | 16.5% | Sep 12, 2016 | ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which all... |
| CVE-2016-6375 | — | — | 0.6% | Sep 12, 2016 | Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102... |
| CVE-2016-3899 | — | — | 0.7% | Sep 11, 2016 | OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x b... |
| CVE-2016-3898 | — | — | 0.4% | Sep 11, 2016 | Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows att... |
| CVE-2016-3897 | — | — | 0.6% | Sep 11, 2016 | The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before ... |
| CVE-2016-3896 | — | — | 0.5% | Sep 11, 2016 | AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attacker... |
| CVE-2016-3895 | — | — | 0.5% | Sep 11, 2016 | Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01... |
| CVE-2016-3894 | — | — | 0.4% | Sep 11, 2016 | The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive informat... |
| CVE-2016-3893 | — | — | 0.5% | Sep 11, 2016 | The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before ... |
| CVE-2016-3892 | — | — | 0.5% | Sep 11, 2016 | The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensi... |
| CVE-2016-3890 | — | — | 0.7% | Sep 11, 2016 | The Java Debug Wire Protocol (JDWP) implementation in adb/sockets.cpp in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5... |
| CVE-2016-3889 | — | — | 0.2% | Sep 11, 2016 | Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Rese... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now