2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2211 | — | — | 53.4% | Jun 30, 2016 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS... |
| CVE-2016-2210 | — | — | 11.4% | Jun 30, 2016 | Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec... |
| CVE-2016-2209 | — | — | 20.9% | Jun 30, 2016 | Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec ... |
| CVE-2016-2207 | — | — | 18.1% | Jun 30, 2016 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS... |
| CVE-2016-5360 | — | — | 42.2% | Jun 30, 2016 | HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service ... |
| CVE-2016-5301 | — | — | 1.9% | Jun 30, 2016 | The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) ... |
| CVE-2016-5020 | — | — | 3.4% | Jun 30, 2016 | F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Reso... |
| CVE-2016-4971 | HIGH | 8.8 | 45.9% | Jun 30, 2016 | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F... |
| CVE-2016-4803 | — | — | 2.2% | Jun 30, 2016 | CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject ar... |
| CVE-2016-4472 | HIGH | 8.1 | 11.9% | Jun 30, 2016 | The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attacke... |
| CVE-2016-4309 | HIGH | 7.5 | 9.4% | Jun 30, 2016 | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers... |
| CVE-2016-3189 | MEDIUM | 6.5 | 15.7% | Jun 30, 2016 | Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash)... |
| CVE-2016-5840 | — | — | 7.8% | Jun 30, 2016 | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad... |
| CVE-2016-5729 | HIGH | 8.2 | 0.4% | Jun 30, 2016 | Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privilege... |
| CVE-2016-5368 | — | — | 1.4% | Jun 30, 2016 | Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consu... |
| CVE-2016-5249 | — | — | 0.6% | Jun 30, 2016 | Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via... |
| CVE-2016-5248 | — | — | 0.3% | Jun 30, 2016 | The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to termi... |
| CVE-2016-5232 | — | — | 0.5% | Jun 30, 2016 | Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B... |
| CVE-2016-5231 | — | — | 0.6% | Jun 30, 2016 | Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef... |
| CVE-2016-5230 | — | — | 0.7% | Jun 30, 2016 | Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef... |
| CVE-2016-4474 | — | — | 0.8% | Jun 30, 2016 | The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterp... |
| CVE-2016-4086 | — | — | 0.3% | Jun 30, 2016 | Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install ar... |
| CVE-2016-4057 | — | — | 1.0% | Jun 30, 2016 | Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource c... |
| CVE-2016-2141 | CRITICAL | 9.8 | 4.7% | Jun 30, 2016 | It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cl... |
| CVE-2016-0349 | — | — | 1.5% | Jun 30, 2016 | IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now