2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-0760——Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute ...
CVE-2016-4654——IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or caus...
CVE-2016-1458——The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x bef...
CVE-2016-1457——The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Ada...
CVE-2016-1365——The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allow...
CVE-2016-6367HIGH7.8Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows loc...
CVE-2016-6366HIGH8.8Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service...
CVE-2016-5847——SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l...
CVE-2016-5845MEDIUM5.5SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca...
CVE-2016-5384HIGH7.8fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequ...
CVE-2016-6214——gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-o...
CVE-2016-6207MEDIUM6.5Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2...
CVE-2016-6161——The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of ...
CVE-2016-6132——The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to caus...
CVE-2016-6597——Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to acce...
CVE-2016-5421HIGH8.1Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly h...
CVE-2016-5420——curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which migh...
CVE-2016-5419——curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allo...
CVE-2016-5408——Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8...
CVE-2016-3329——Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence of files via a craft...
CVE-2016-3327——Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted w...
CVE-2016-3326——Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted w...
CVE-2016-3322——Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Mi...
CVE-2016-3321——Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the f...
CVE-2016-3320——Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now