2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8910MEDIUM6The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrator...
CVE-2016-8909MEDIUM6The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to...
CVE-2016-8870The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before...
CVE-2016-8869The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before...
CVE-2016-8669MEDIUM6The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrat...
CVE-2016-8668MEDIUM6The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrator...
CVE-2016-8667MEDIUM6The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause ...
CVE-2016-8578MEDIUM6The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administra...
CVE-2016-8577MEDIUM6Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators ...
CVE-2016-8576MEDIUM6The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to c...
CVE-2016-9190Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" appro...
CVE-2016-9189Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file"...
CVE-2016-9188Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary w...
CVE-2016-9187Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remo...
CVE-2016-9186Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows re...
CVE-2016-9185In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery re...
CVE-2016-9184In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to con...
CVE-2016-9183In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into se...
CVE-2016-9182Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user...
CVE-2016-9177Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the...
CVE-2016-9176Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by l...
CVE-2016-6455A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could all...
CVE-2016-6454A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfi...
CVE-2016-6453A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote a...
CVE-2016-6452A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remo...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now