2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4440 | HIGH | 7.8 | 0.4% | Jun 27, 2016 | arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to o... |
| CVE-2016-3949 | — | — | 4.5% | Jun 27, 2016 | Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU... |
| CVE-2016-3713 | — | — | 0.3% | Jun 27, 2016 | The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows gue... |
| CVE-2016-3707 | — | — | 3.4% | Jun 27, 2016 | The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in ... |
| CVE-2016-1583 | HIGH | 7.8 | 1.4% | Jun 27, 2016 | The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga... |
| CVE-2016-0758 | HIGH | 7.8 | 0.4% | Jun 27, 2016 | Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ... |
| CVE-2016-0301 | — | — | 2.8% | Jun 26, 2016 | Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 ... |
| CVE-2016-0279 | — | — | 2.7% | Jun 26, 2016 | Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 ... |
| CVE-2016-0278 | — | — | 2.9% | Jun 26, 2016 | Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 ... |
| CVE-2016-0277 | — | — | 2.7% | Jun 26, 2016 | Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 ... |
| CVE-2016-0259 | — | — | 0.3% | Jun 26, 2016 | runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and o... |
| CVE-2016-5087 | — | — | 0.6% | Jun 26, 2016 | Alertus Desktop Notification before 2.9.31.1710 on OS X uses weak permissions for configuration files and unspecified ot... |
| CVE-2016-4513 | — | — | 0.9% | Jun 26, 2016 | Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2.651 for PowerMeter ... |
| CVE-2016-2901 | — | — | 0.9% | Jun 26, 2016 | Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 thr... |
| CVE-2016-4828 | MEDIUM | 6.5 | 1.8% | Jun 25, 2016 | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to ob... |
| CVE-2016-4827 | MEDIUM | 6.1 | 1.5% | Jun 25, 2016 | Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remot... |
| CVE-2016-4826 | MEDIUM | 6.1 | 1.5% | Jun 25, 2016 | Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remot... |
| CVE-2016-4825 | MEDIUM | 5.6 | 2.9% | Jun 25, 2016 | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection ... |
| CVE-2016-4824 | — | — | 1.4% | Jun 25, 2016 | The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the n... |
| CVE-2016-4823 | — | — | 1.9% | Jun 25, 2016 | Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors. |
| CVE-2016-4822 | HIGH | 8 | 1.1% | Jun 25, 2016 | Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors. |
| CVE-2016-1193 | — | — | 1.6% | Jun 25, 2016 | Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vect... |
| CVE-2016-1190 | — | — | 1.1% | Jun 25, 2016 | Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading v... |
| CVE-2016-1189 | — | — | 1.2% | Jun 25, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, cre... |
| CVE-2016-1188 | — | — | 1.1% | Jun 25, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now