2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1000282Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlie...
CVE-2016-1000276Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000010. Reason: This candidate is a duplicate...
CVE-2016-1000271Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/ind...
CVE-2016-10741In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) becau...
CVE-2016-10740Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn th...
CVE-2016-10739In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that ...
CVE-2016-9778HIGH7.5An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature...
CVE-2016-10738Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
CVE-2016-10737Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
CVE-2016-7576In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory h...
CVE-2016-4644In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade is...
CVE-2016-4643In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation i...
CVE-2016-4642In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authenti...
CVE-2016-10736The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?pag...
CVE-2016-9651A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a ...
CVE-2016-10403Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to...
CVE-2016-10735In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a differen...
CVE-2016-10502While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identit...
CVE-2016-8489Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10242. Reason: This candidate is a reservation...
CVE-2016-9749MEDIUM4IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass s...
CVE-2016-2123HIGH8.8A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem...
CVE-2016-2120HIGH7.5An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authoriz...
CVE-2016-6328HIGH8.1A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can ...
CVE-2016-2125MEDIUM6.5It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos au...
CVE-2016-6343MEDIUM6.1JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now