2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6304HIGH7.5Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote at...
CVE-2016-6980Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspe...
CVE-2016-6038Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3...
CVE-2016-6913Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to in...
CVE-2016-6901Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR36...
CVE-2016-6827Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated use...
CVE-2016-6826Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a craft...
CVE-2016-6172PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (me...
CVE-2016-6153os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow loca...
CVE-2016-6142SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYS...
CVE-2016-4972OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x b...
CVE-2016-3639SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified H...
CVE-2016-7162HIGH7.5The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to del...
CVE-2016-7142The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows...
CVE-2016-6518Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a de...
CVE-2016-5746libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary fi...
CVE-2016-8279The video driver in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B362, CRR-UL20 before CRR-UL20C00...
CVE-2016-7098Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow...
CVE-2016-6840Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 al...
CVE-2016-6276Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain ro...
CVE-2016-5406The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticate...
CVE-2016-5395Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger befo...
CVE-2016-4993CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Applicati...
CVE-2016-4303CRITICAL9.8The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to c...
CVE-2016-3110mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now