2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7154 | — | — | 0.5% | Sep 21, 2016 | Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a... |
| CVE-2016-7143 | — | — | 1.1% | Sep 21, 2016 | The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate f... |
| CVE-2016-7094 | — | — | 0.4% | Sep 21, 2016 | Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow pagi... |
| CVE-2016-7093 | — | — | 0.4% | Sep 21, 2016 | Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain... |
| CVE-2016-7092 | — | — | 0.4% | Sep 21, 2016 | The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS pr... |
| CVE-2016-6801 | — | — | 2.3% | Sep 21, 2016 | Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit... |
| CVE-2016-6354 | — | — | 8.8% | Sep 21, 2016 | Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attacke... |
| CVE-2016-6250 | — | — | 6.3% | Sep 21, 2016 | Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (... |
| CVE-2016-6159 | — | — | 1.1% | Sep 21, 2016 | The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers... |
| CVE-2016-6158 | — | — | 1.2% | Sep 21, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R... |
| CVE-2016-5844 | — | — | 4.1% | Sep 21, 2016 | Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (appl... |
| CVE-2016-5427 | — | — | 63.0% | Sep 21, 2016 | PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows re... |
| CVE-2016-5426 | — | — | 30.6% | Sep 21, 2016 | PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU... |
| CVE-2016-5418 | — | — | 4.7% | Sep 21, 2016 | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which mig... |
| CVE-2016-5017 | — | — | 7.8% | Sep 21, 2016 | Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch ... |
| CVE-2016-4969 | — | — | 2.3% | Sep 21, 2016 | Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers... |
| CVE-2016-4968 | — | — | 2.7% | Sep 21, 2016 | The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated... |
| CVE-2016-4967 | — | — | 2.7% | Sep 21, 2016 | Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information f... |
| CVE-2016-4966 | — | — | 2.2% | Sep 21, 2016 | The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users... |
| CVE-2016-4965 | — | — | 4.1% | Sep 21, 2016 | Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup funct... |
| CVE-2016-4809 | — | — | 4.7% | Sep 21, 2016 | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allow... |
| CVE-2016-4302 | — | — | 4.8% | Sep 21, 2016 | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 a... |
| CVE-2016-4301 | — | — | 3.7% | Sep 21, 2016 | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2... |
| CVE-2016-4300 | — | — | 4.9% | Sep 21, 2016 | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 al... |
| CVE-2016-6530 | — | — | 3.1% | Sep 21, 2016 | Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allow... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now