2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3139 | — | — | 1.8% | Apr 27, 2016 | The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate... |
| CVE-2016-3134 | — | — | 1.2% | Apr 27, 2016 | The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local us... |
| CVE-2016-2847 | — | — | 0.6% | Apr 27, 2016 | fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to ... |
| CVE-2016-2550 | — | — | 0.5% | Apr 27, 2016 | The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory co... |
| CVE-2016-2549 | — | — | 0.5% | Apr 27, 2016 | sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local use... |
| CVE-2016-2548 | — | — | 0.5% | Apr 27, 2016 | sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which all... |
| CVE-2016-2547 | — | — | 0.3% | Apr 27, 2016 | sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instan... |
| CVE-2016-2546 | — | — | 0.3% | Apr 27, 2016 | sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a... |
| CVE-2016-2545 | — | — | 0.3% | Apr 27, 2016 | The snd_timer_interrupt function in sound/core/timer.c in the Linux kernel before 4.4.1 does not properly maintain a cer... |
| CVE-2016-2544 | — | — | 0.3% | Apr 27, 2016 | Race condition in the queue_delete function in sound/core/seq/seq_queue.c in the Linux kernel before 4.4.1 allows local ... |
| CVE-2016-2543 | — | — | 0.5% | Apr 27, 2016 | The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not ver... |
| CVE-2016-2384 | — | — | 3.7% | Apr 27, 2016 | Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows p... |
| CVE-2016-2184 | — | — | 1.9% | Apr 27, 2016 | The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.... |
| CVE-2016-2085 | — | — | 0.4% | Apr 27, 2016 | The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy ... |
| CVE-2016-2069 | — | — | 0.3% | Apr 27, 2016 | Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering... |
| CVE-2016-0774 | — | — | 0.3% | Apr 27, 2016 | The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux packag... |
| CVE-2016-3082 | — | — | 20.8% | Apr 26, 2016 | XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote at... |
| CVE-2016-3081 | — | — | 94.2% | Apr 26, 2016 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a... |
| CVE-2016-1601 | — | — | 2.5% | Apr 26, 2016 | yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/... |
| CVE-2016-2346 | — | — | 0.9% | Apr 25, 2016 | Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-t... |
| CVE-2016-2333 | — | — | 0.8% | Apr 25, 2016 | SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encry... |
| CVE-2016-2332 | — | — | 2.8% | Apr 25, 2016 | flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01... |
| CVE-2016-2331 | — | — | 2.5% | Apr 25, 2016 | The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a d... |
| CVE-2016-1202 | — | — | 0.4% | Apr 25, 2016 | Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan ho... |
| CVE-2016-1185 | — | — | 0.7% | Apr 25, 2016 | The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now