2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2470 | — | — | 0.4% | Jun 13, 2016 | The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via... |
| CVE-2016-2469 | — | — | 0.6% | Jun 13, 2016 | The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attackers to gain privileges... |
| CVE-2016-2468 | — | — | 0.8% | Jun 13, 2016 | The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privi... |
| CVE-2016-2467 | — | — | 0.4% | Jun 13, 2016 | The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5 devices allows attackers to gain privileges via a craf... |
| CVE-2016-2466 | — | — | 0.4% | Jun 13, 2016 | The Qualcomm sound driver in Android before 2016-06-01 on Nexus 6 devices allows attackers to gain privileges via a craf... |
| CVE-2016-2465 | — | — | 0.5% | Jun 13, 2016 | The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privil... |
| CVE-2016-2464 | — | — | 1.8% | Jun 13, 2016 | libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201... |
| CVE-2016-2463 | — | — | 0.9% | Jun 13, 2016 | Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x ... |
| CVE-2016-2066 | HIGH | 7.8 | 1.4% | Jun 13, 2016 | Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (... |
| CVE-2016-2061 | HIGH | 7.8 | 1.1% | Jun 13, 2016 | Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (Q... |
| CVE-2016-5233 | — | — | 0.5% | Jun 10, 2016 | Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 befor... |
| CVE-2016-5118 | CRITICAL | 9.8 | 49.3% | Jun 10, 2016 | The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbit... |
| CVE-2016-4429 | MEDIUM | 5.9 | 4.0% | Jun 10, 2016 | Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) ... |
| CVE-2016-3720 | CRITICAL | 9.8 | 2.7% | Jun 10, 2016 | XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xm... |
| CVE-2016-3706 | HIGH | 7.5 | 5.8% | Jun 10, 2016 | Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc o... |
| CVE-2016-3085 | — | — | 2.9% | Jun 10, 2016 | Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-... |
| CVE-2016-2786 | CRITICAL | 9.8 | 1.6% | Jun 10, 2016 | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not prope... |
| CVE-2016-2785 | CRITICAL | 9.8 | 2.9% | Jun 10, 2016 | Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow... |
| CVE-2016-4527 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive ... |
| CVE-2016-4524 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allo... |
| CVE-2016-4516 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users ... |
| CVE-2016-4511 | — | — | 0.3% | Jun 10, 2016 | ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local... |
| CVE-2016-4495 | — | — | 1.2% | Jun 10, 2016 | KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictio... |
| CVE-2016-4494 | — | — | 0.6% | Jun 10, 2016 | Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows r... |
| CVE-2016-4328 | — | — | 4.0% | Jun 10, 2016 | MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which m... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now