2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3742 | — | — | 1.1% | Jul 11, 2016 | decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra mode, which allows re... |
| CVE-2016-3741 | — | — | 1.4% | Jul 11, 2016 | The H.264 decoder in mediaserver in Android 6.x before 2016-07-01 does not initialize certain slice data, which allows r... |
| CVE-2016-2508 | — | — | 1.7% | Jul 11, 2016 | media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5... |
| CVE-2016-2507 | — | — | 1.2% | Jul 11, 2016 | Integer overflow in codecs/on2/h264dec/source/h264bsd_storage.c in libstagefright in mediaserver in Android 4.x before 4... |
| CVE-2016-2506 | — | — | 1.7% | Jul 11, 2016 | DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, a... |
| CVE-2016-2505 | — | — | 1.1% | Jul 11, 2016 | mpeg2ts/ATSParser.cpp in libstagefright in mediaserver in Android 6.x before 2016-07-01 does not validate a certain sect... |
| CVE-2016-2503 | — | — | 0.5% | Jul 11, 2016 | The Qualcomm GPU driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via ... |
| CVE-2016-2502 | — | — | 0.5% | Jul 11, 2016 | drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows ... |
| CVE-2016-2501 | — | — | 0.5% | Jul 11, 2016 | The Qualcomm camera driver in Android before 2016-07-05 on Nexus 5X, 6, 6P, and 7 (2013) devices allows attackers to gai... |
| CVE-2016-4463 | — | — | 14.2% | Jul 8, 2016 | Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of se... |
| CVE-2016-4324 | — | — | 2.8% | Jul 8, 2016 | Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted... |
| CVE-2016-3794 | — | — | — | Jul 8, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3814. Reason: This candidate is a reservation ... |
| CVE-2016-2945 | — | — | 1.8% | Jul 8, 2016 | The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Libert... |
| CVE-2016-2889 | — | — | 0.5% | Jul 8, 2016 | Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Re... |
| CVE-2016-2888 | — | — | 0.7% | Jul 8, 2016 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting... |
| CVE-2016-0350 | — | — | 0.6% | Jul 8, 2016 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting... |
| CVE-2016-0315 | — | — | 1.0% | Jul 8, 2016 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and ... |
| CVE-2016-0314 | — | — | 0.9% | Jul 8, 2016 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and ... |
| CVE-2016-0313 | — | — | 0.6% | Jul 8, 2016 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting... |
| CVE-2016-0287 | — | — | 0.4% | Jul 8, 2016 | IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors. |
| CVE-2016-0271 | — | — | 0.3% | Jul 8, 2016 | The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a s... |
| CVE-2016-0252 | — | — | 0.3% | Jul 8, 2016 | IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users t... |
| CVE-2016-2923 | — | — | 2.3% | Jul 7, 2016 | IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the... |
| CVE-2016-1442 | — | — | 3.2% | Jul 7, 2016 | The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to ex... |
| CVE-2016-0389 | — | — | 1.9% | Jul 7, 2016 | Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now