2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9111——Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r...
CVE-2016-8910MEDIUM6The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrator...
CVE-2016-8909MEDIUM6The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to...
CVE-2016-8870——The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before...
CVE-2016-8869——The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before...
CVE-2016-8669MEDIUM6The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrat...
CVE-2016-8668MEDIUM6The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrator...
CVE-2016-8667MEDIUM6The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause ...
CVE-2016-8578MEDIUM6The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administra...
CVE-2016-8577MEDIUM6Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators ...
CVE-2016-8576MEDIUM6The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to c...
CVE-2016-9190——Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" appro...
CVE-2016-9189——Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file"...
CVE-2016-9188——Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary w...
CVE-2016-9187——Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remo...
CVE-2016-9186——Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows re...
CVE-2016-9185——In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery re...
CVE-2016-9184——In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to con...
CVE-2016-9183——In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into se...
CVE-2016-9182——Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user...
CVE-2016-9177——Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the...
CVE-2016-9176——Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by l...
CVE-2016-6455——A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could all...
CVE-2016-6454——A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfi...
CVE-2016-6453——A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote a...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now