2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1397 | — | — | 1.8% | Jun 19, 2016 | Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devic... |
| CVE-2016-1396 | — | — | 1.0% | Jun 19, 2016 | Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware bef... |
| CVE-2016-1395 | — | — | 4.8% | Jun 19, 2016 | The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware be... |
| CVE-2016-1224 | MEDIUM | 6.1 | 1.6% | Jun 19, 2016 | CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.... |
| CVE-2016-1223 | MEDIUM | 5.3 | 4.2% | Jun 19, 2016 | Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-F... |
| CVE-2016-1183 | — | — | 1.8% | Jun 19, 2016 | NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Appli... |
| CVE-2016-1432 | — | — | 1.6% | Jun 18, 2016 | Cisco IOS XE 3.15S and 3.16S on cBR-8 Converged Broadband Router devices allows remote authenticated users to cause a de... |
| CVE-2016-1431 | — | — | 0.8% | Jun 18, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 all... |
| CVE-2016-1427 | — | — | 1.8% | Jun 18, 2016 | The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and... |
| CVE-2016-5433 | — | — | 0.4% | Jun 17, 2016 | Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified ve... |
| CVE-2016-5363 | — | — | 3.2% | Jun 17, 2016 | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an int... |
| CVE-2016-5362 | — | — | 3.3% | Jun 17, 2016 | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an int... |
| CVE-2016-3643 | HIGH | 7.8 | 3.7% | Jun 17, 2016 | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio... |
| CVE-2016-3642 | — | — | 13.3% | Jun 17, 2016 | The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary comm... |
| CVE-2016-5300 | — | — | 6.5% | Jun 16, 2016 | The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attacker... |
| CVE-2016-3687 | — | — | 1.2% | Jun 16, 2016 | Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.... |
| CVE-2016-3062 | — | — | 4.1% | Jun 16, 2016 | The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to c... |
| CVE-2016-2841 | — | — | 0.4% | Jun 16, 2016 | The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local gues... |
| CVE-2016-2538 | — | — | 0.4% | Jun 16, 2016 | Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest ... |
| CVE-2016-2392 | — | — | 0.4% | Jun 16, 2016 | The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly valid... |
| CVE-2016-2391 | MEDIUM | 5 | 0.4% | Jun 16, 2016 | The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administ... |
| CVE-2016-5361 | — | — | 2.8% | Jun 16, 2016 | programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers t... |
| CVE-2016-4171 | CRITICAL | 9.8 | 19.9% | Jun 16, 2016 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code... |
| CVE-2016-4167 | — | — | 5.4% | Jun 16, 2016 | Adobe DNG Software Development Kit (SDK) before 1.4 2016 allows attackers to execute arbitrary code or cause a denial of... |
| CVE-2016-4166 | HIGH | 8.8 | 3.9% | Jun 16, 2016 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now