2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4265 | — | — | 5.6% | Aug 26, 2016 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro... |
| CVE-2016-4119 | — | — | 4.0% | Aug 26, 2016 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro... |
| CVE-2016-5383 | — | — | 2.6% | Aug 26, 2016 | The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "... |
| CVE-2016-5023 | — | — | 3.0% | Aug 26, 2016 | Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF... |
| CVE-2016-1497 | — | — | 1.5% | Aug 26, 2016 | The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 H... |
| CVE-2016-6369 | — | — | 0.4% | Aug 25, 2016 | Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows l... |
| CVE-2016-5681 | CRITICAL | 9.8 | 11.9% | Aug 25, 2016 | Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx befor... |
| CVE-2016-5673 | — | — | 1.9% | Aug 25, 2016 | UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to ... |
| CVE-2016-4657 | HIGH | 8.8 | 66.8% | Aug 25, 2016 | WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory ... |
| CVE-2016-4656 | HIGH | 7.8 | 23.6% | Aug 25, 2016 | The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia... |
| CVE-2016-4655 | MEDIUM | 5.5 | 33.4% | Aug 25, 2016 | The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app. |
| CVE-2016-6231 | — | — | 1.3% | Aug 25, 2016 | Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-mid... |
| CVE-2016-4069 | — | — | 2.7% | Aug 25, 2016 | Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the ... |
| CVE-2016-7089 | — | — | 1.2% | Aug 24, 2016 | WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifco... |
| CVE-2016-6909 | — | — | 49.9% | Aug 24, 2016 | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 ... |
| CVE-2016-5812 | — | — | 0.3% | Aug 24, 2016 | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password stor... |
| CVE-2016-5799 | — | — | 4.0% | Aug 24, 2016 | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict au... |
| CVE-2016-5650 | — | — | 1.7% | Aug 24, 2016 | ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2 configuration setting, which allows remote attackers to tri... |
| CVE-2016-5645 | HIGH | 7.3 | 29.4% | Aug 24, 2016 | Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32B... |
| CVE-2016-5081 | — | — | 3.3% | Aug 24, 2016 | ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obt... |
| CVE-2016-6365 | — | — | 0.9% | Aug 23, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and ... |
| CVE-2016-6364 | — | — | 2.2% | Aug 23, 2016 | The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to ... |
| CVE-2016-6355 | — | — | 2.9% | Aug 23, 2016 | Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows... |
| CVE-2016-1484 | — | — | 1.6% | Aug 23, 2016 | Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive appl... |
| CVE-2016-1477 | — | — | 1.0% | Aug 23, 2016 | Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now