2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7418The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers...
CVE-2016-7417ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating...
CVE-2016-7416ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale l...
CVE-2016-7415Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) throug...
CVE-2016-7414The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_...
CVE-2016-7413Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7...
CVE-2016-7412ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the U...
CVE-2016-7411ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote at...
CVE-2016-6644EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase document...
CVE-2016-1482Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into a...
CVE-2016-6938Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15...
CVE-2016-6937Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro...
CVE-2016-6407Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of ser...
CVE-2016-6401Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, all...
CVE-2016-5843Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Op...
CVE-2016-7420Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling t...
CVE-2016-6936Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, whi...
CVE-2016-6303CRITICAL9.8Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers t...
CVE-2016-6302The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validatio...
CVE-2016-4263Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspe...
CVE-2016-4262Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2016-4261Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2016-4260Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2016-4259Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2016-4258Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now