2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4432CRITICAL9.1The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to b...
CVE-2016-3697HIGH7.8libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a po...
CVE-2016-3094MEDIUM5.9PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allow...
CVE-2016-3088CRITICAL9.8The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr...
CVE-2016-3075——Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) befo...
CVE-2016-2175——Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-depe...
CVE-2016-1234——Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is...
CVE-2016-4500——Moxa UC-7408 LX-Plus devices allow remote authenticated users to write to the firmware, and consequently render a device...
CVE-2016-0288——IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenti...
CVE-2016-4785——A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;...
CVE-2016-4784——A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;...
CVE-2016-4521——Sixnet BT-5xxx and BT-6xxx M2M devices before 3.8.21 and 3.9.x before 3.9.8 have hardcoded credentials, which allows rem...
CVE-2016-4506——Cross-site request forgery (CSRF) vulnerability on Resource Data Management (RDM) Intuitive 650 TDB Controller devices b...
CVE-2016-4505——Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allow remote authenticated users to mo...
CVE-2016-4502——Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier allows remote attackers to bypass intended...
CVE-2016-4501——Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier mishandles sessions, which allows remote a...
CVE-2016-2295——Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build...
CVE-2016-2286——Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build...
CVE-2016-2285——Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, M...
CVE-2016-0879HIGH7.5Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing t...
CVE-2016-0878HIGH7.5Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by se...
CVE-2016-0877HIGH7.5Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (m...
CVE-2016-0876HIGH7.5Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a co...
CVE-2016-0875HIGH7.5Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a craft...
CVE-2016-4118——Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now