2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3159 | — | — | 0.4% | Apr 13, 2016 | The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when r... |
| CVE-2016-3158 | — | — | 0.4% | Apr 13, 2016 | The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when runn... |
| CVE-2016-3069 | — | — | 5.0% | Apr 13, 2016 | Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git reposi... |
| CVE-2016-3068 | — | — | 5.4% | Apr 13, 2016 | Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subr... |
| CVE-2016-2533 | — | — | 4.0% | Apr 13, 2016 | Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) ... |
| CVE-2016-2515 | — | — | 3.4% | Apr 13, 2016 | Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial o... |
| CVE-2016-2228 | — | — | 1.9% | Apr 13, 2016 | Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 an... |
| CVE-2016-2191 | — | — | 3.5% | Apr 13, 2016 | The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of s... |
| CVE-2016-2084 | — | — | 0.8% | Apr 13, 2016 | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 be... |
| CVE-2016-2058 | — | — | 1.2% | Apr 13, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymo... |
| CVE-2016-2057 | — | — | 0.5% | Apr 13, 2016 | lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC messag... |
| CVE-2016-2056 | — | — | 54.5% | Apr 13, 2016 | xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via... |
| CVE-2016-2055 | — | — | 17.9% | Apr 13, 2016 | xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files ... |
| CVE-2016-2054 | — | — | 5.6% | Apr 13, 2016 | Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attac... |
| CVE-2016-0775 | — | — | 2.7% | Apr 13, 2016 | Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attacker... |
| CVE-2016-0740 | — | — | 2.4% | Apr 13, 2016 | Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote att... |
| CVE-2016-4007 | — | — | 2.5% | Apr 13, 2016 | Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and be... |
| CVE-2016-2780 | — | — | 0.3% | Apr 13, 2016 | Untrusted search path vulnerability in Huawei UTPS before UTPS-V200R003B015D15SP00C983 allows local users to execute arb... |
| CVE-2016-2116 | — | — | 3.0% | Apr 13, 2016 | Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a d... |
| CVE-2016-1577 | — | — | 3.3% | Apr 13, 2016 | Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers t... |
| CVE-2016-1496 | — | — | 0.6% | Apr 13, 2016 | The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B... |
| CVE-2016-1495 | — | — | 0.8% | Apr 13, 2016 | Integer overflow in the graphics drivers in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01,... |
| CVE-2016-2001 | — | — | 2.0% | Apr 12, 2016 | HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive informati... |
| CVE-2016-1377 | — | — | 1.0% | Apr 12, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitr... |
| CVE-2016-1376 | — | — | 1.7% | Apr 12, 2016 | Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CR... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now