2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5350 | — | — | 2.8% | Aug 7, 2016 | epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 ... |
| CVE-2016-4029 | HIGH | 8.6 | 4.6% | Aug 7, 2016 | WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, wh... |
| CVE-2016-6128 | HIGH | 7.5 | 6.7% | Aug 7, 2016 | The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP befor... |
| CVE-2016-5773 | — | — | 9.1% | Aug 7, 2016 | php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with... |
| CVE-2016-5772 | CRITICAL | 9.8 | 9.8% | Aug 7, 2016 | Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.... |
| CVE-2016-5771 | CRITICAL | 9.8 | 15.1% | Aug 7, 2016 | spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize ... |
| CVE-2016-5770 | CRITICAL | 9.8 | 7.2% | Aug 7, 2016 | Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5... |
| CVE-2016-5769 | — | — | 8.2% | Aug 7, 2016 | Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before... |
| CVE-2016-5768 | — | — | 9.7% | Aug 7, 2016 | Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in ... |
| CVE-2016-5767 | — | — | 6.7% | Aug 7, 2016 | Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used ... |
| CVE-2016-5766 | — | — | 7.6% | Aug 7, 2016 | Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used ... |
| CVE-2016-5116 | — | — | 3.7% | Aug 7, 2016 | gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows... |
| CVE-2016-5114 | — | — | 4.5% | Aug 7, 2016 | sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of th... |
| CVE-2016-5096 | — | — | 4.4% | Aug 7, 2016 | Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote... |
| CVE-2016-5095 | — | — | 2.6% | Aug 7, 2016 | Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x befor... |
| CVE-2016-5094 | — | — | 4.6% | Aug 7, 2016 | Integer overflow in the php_html_entities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 a... |
| CVE-2016-5093 | — | — | 5.5% | Aug 7, 2016 | The get_icu_value_internal function in ext/intl/locale/locale_methods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7... |
| CVE-2016-3132 | — | — | 11.7% | Aug 7, 2016 | Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6... |
| CVE-2016-3078 | CRITICAL | 9.8 | 57.6% | Aug 7, 2016 | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia... |
| CVE-2016-6513 | — | — | 2.1% | Aug 6, 2016 | epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 2.x before 2.0.5 does not restrict the recursion dept... |
| CVE-2016-6512 | — | — | 7.6% | Aug 6, 2016 | epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, whi... |
| CVE-2016-6511 | — | — | 2.1% | Aug 6, 2016 | epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of servic... |
| CVE-2016-6510 | — | — | 2.3% | Aug 6, 2016 | Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before ... |
| CVE-2016-6509 | — | — | 2.1% | Aug 6, 2016 | epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles c... |
| CVE-2016-6508 | — | — | 2.3% | Aug 6, 2016 | epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorr... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now