2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5097 | — | — | 1.5% | Jul 5, 2016 | phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navi... |
| CVE-2016-4957 | HIGH | 7.5 | 44.9% | Jul 5, 2016 | ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. ... |
| CVE-2016-4956 | MEDIUM | 5.3 | 16.1% | Jul 5, 2016 | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and tim... |
| CVE-2016-4955 | MEDIUM | 5.9 | 8.8% | Jul 5, 2016 | ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-vari... |
| CVE-2016-4954 | HIGH | 7.5 | 13.3% | Jul 5, 2016 | The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial o... |
| CVE-2016-4953 | HIGH | 7.5 | 17.2% | Jul 5, 2016 | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilizatio... |
| CVE-2016-4465 | — | — | 10.6% | Jul 4, 2016 | The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to caus... |
| CVE-2016-4438 | — | — | 17.2% | Jul 4, 2016 | The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a craft... |
| CVE-2016-4433 | — | — | 10.0% | Jul 4, 2016 | Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redir... |
| CVE-2016-4431 | — | — | 10.0% | Jul 4, 2016 | Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redir... |
| CVE-2016-4430 | — | — | 4.0% | Jul 4, 2016 | Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site... |
| CVE-2016-3092 | — | — | 35.9% | Jul 4, 2016 | The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x bef... |
| CVE-2016-1182 | — | — | 25.9% | Jul 4, 2016 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which a... |
| CVE-2016-1181 | — | — | 13.2% | Jul 4, 2016 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, whic... |
| CVE-2016-5849 | LOW | 2.5 | 0.3% | Jul 4, 2016 | Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database s... |
| CVE-2016-5848 | MEDIUM | 6.7 | 0.3% | Jul 4, 2016 | Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local ... |
| CVE-2016-0899 | — | — | 0.8% | Jul 4, 2016 | EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain se... |
| CVE-2016-6130 | — | — | 0.3% | Jul 3, 2016 | Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows... |
| CVE-2016-4998 | — | — | 1.9% | Jul 3, 2016 | The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local ... |
| CVE-2016-4997 | HIGH | 7.8 | 5.7% | Jul 3, 2016 | The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux... |
| CVE-2016-3955 | CRITICAL | 9.8 | 25.9% | Jul 3, 2016 | The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attacke... |
| CVE-2016-2894 | — | — | 0.3% | Jul 3, 2016 | IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 befor... |
| CVE-2016-2863 | — | — | 0.6% | Jul 3, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, a... |
| CVE-2016-2862 | — | — | 1.1% | Jul 3, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative i... |
| CVE-2016-2074 | — | — | 6.2% | Jul 3, 2016 | Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now