2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7418 | — | — | 11.4% | Sep 17, 2016 | The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers... |
| CVE-2016-7417 | — | — | 6.8% | Sep 17, 2016 | ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating... |
| CVE-2016-7416 | — | — | 6.7% | Sep 17, 2016 | ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale l... |
| CVE-2016-7415 | — | — | 5.8% | Sep 17, 2016 | Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) throug... |
| CVE-2016-7414 | — | — | 6.8% | Sep 17, 2016 | The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_... |
| CVE-2016-7413 | — | — | 6.7% | Sep 17, 2016 | Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7... |
| CVE-2016-7412 | — | — | 8.8% | Sep 17, 2016 | ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the U... |
| CVE-2016-7411 | — | — | 5.6% | Sep 17, 2016 | ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote at... |
| CVE-2016-6644 | — | — | 1.9% | Sep 17, 2016 | EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase document... |
| CVE-2016-1482 | — | — | 4.0% | Sep 17, 2016 | Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into a... |
| CVE-2016-6938 | — | — | 8.7% | Sep 17, 2016 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15... |
| CVE-2016-6937 | — | — | 6.6% | Sep 17, 2016 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro... |
| CVE-2016-6407 | — | — | 2.5% | Sep 17, 2016 | Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of ser... |
| CVE-2016-6401 | — | — | 0.8% | Sep 17, 2016 | Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, all... |
| CVE-2016-5843 | — | — | 3.2% | Sep 17, 2016 | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Op... |
| CVE-2016-7420 | — | — | 2.3% | Sep 16, 2016 | Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling t... |
| CVE-2016-6936 | — | — | 3.8% | Sep 16, 2016 | Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, whi... |
| CVE-2016-6303 | CRITICAL | 9.8 | 32.0% | Sep 16, 2016 | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers t... |
| CVE-2016-6302 | — | — | 26.4% | Sep 16, 2016 | The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validatio... |
| CVE-2016-4263 | — | — | 5.8% | Sep 16, 2016 | Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspe... |
| CVE-2016-4262 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4261 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4260 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4259 | — | — | 4.8% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
| CVE-2016-4258 | — | — | 5.0% | Sep 16, 2016 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corr... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now