2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-2465The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privil...
CVE-2016-2464libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201...
CVE-2016-2463Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x ...
CVE-2016-5233Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 befor...
CVE-2016-3085Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-...
CVE-2016-4527ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive ...
CVE-2016-4524ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allo...
CVE-2016-4516ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users ...
CVE-2016-4511ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local...
CVE-2016-4495KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictio...
CVE-2016-4494Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows r...
CVE-2016-4328MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which m...
CVE-2016-4326The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary cod...
CVE-2016-1421A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute co...
CVE-2016-1420The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3...
CVE-2016-1419Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload)...
CVE-2016-0916EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote a...
CVE-2016-0910EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI us...
CVE-2016-4449XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, ...
CVE-2016-4447The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denia...
CVE-2016-2150SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface p...
CVE-2016-1582LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which ...
CVE-2016-1581LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which a...
CVE-2016-0749The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or poss...
CVE-2016-4532Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2....

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now