2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2465 | — | — | 0.5% | Jun 13, 2016 | The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privil... |
| CVE-2016-2464 | — | — | 1.8% | Jun 13, 2016 | libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201... |
| CVE-2016-2463 | — | — | 0.9% | Jun 13, 2016 | Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x ... |
| CVE-2016-5233 | — | — | 0.5% | Jun 10, 2016 | Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 befor... |
| CVE-2016-3085 | — | — | 2.9% | Jun 10, 2016 | Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-... |
| CVE-2016-4527 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive ... |
| CVE-2016-4524 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allo... |
| CVE-2016-4516 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users ... |
| CVE-2016-4511 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local... |
| CVE-2016-4495 | — | — | 1.2% | Jun 10, 2016 | KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictio... |
| CVE-2016-4494 | — | — | 0.6% | Jun 10, 2016 | Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows r... |
| CVE-2016-4328 | — | — | 4.0% | Jun 10, 2016 | MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which m... |
| CVE-2016-4326 | — | — | 4.2% | Jun 10, 2016 | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary cod... |
| CVE-2016-1421 | — | — | 4.1% | Jun 10, 2016 | A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute co... |
| CVE-2016-1420 | — | — | 0.4% | Jun 10, 2016 | The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3... |
| CVE-2016-1419 | — | — | 0.7% | Jun 10, 2016 | Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload)... |
| CVE-2016-0916 | — | — | 7.7% | Jun 10, 2016 | EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote a... |
| CVE-2016-0910 | — | — | 0.3% | Jun 10, 2016 | EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI us... |
| CVE-2016-4449 | — | — | 1.7% | Jun 9, 2016 | XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, ... |
| CVE-2016-4447 | — | — | 13.6% | Jun 9, 2016 | The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denia... |
| CVE-2016-2150 | — | — | 0.4% | Jun 9, 2016 | SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface p... |
| CVE-2016-1582 | — | — | 0.3% | Jun 9, 2016 | LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which ... |
| CVE-2016-1581 | — | — | 0.3% | Jun 9, 2016 | LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which a... |
| CVE-2016-0749 | — | — | 8.5% | Jun 9, 2016 | The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or poss... |
| CVE-2016-4532 | — | — | 27.6% | Jun 9, 2016 | Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now