2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4794 | HIGH | 7.8 | 0.5% | May 23, 2016 | Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of serv... |
| CVE-2016-4581 | — | — | 0.6% | May 23, 2016 | fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involv... |
| CVE-2016-4580 | — | — | 4.2% | May 23, 2016 | The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly ini... |
| CVE-2016-4578 | — | — | 1.2% | May 23, 2016 | sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local us... |
| CVE-2016-4569 | — | — | 0.8% | May 23, 2016 | The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain d... |
| CVE-2016-4568 | HIGH | 7.8 | 0.4% | May 23, 2016 | drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of servic... |
| CVE-2016-4565 | HIGH | 7.8 | 0.5% | May 23, 2016 | The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows... |
| CVE-2016-4558 | HIGH | 7 | 0.9% | May 23, 2016 | The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a deni... |
| CVE-2016-4557 | HIGH | 7.8 | 10.2% | May 23, 2016 | The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai... |
| CVE-2016-4486 | — | — | 1.7% | May 23, 2016 | The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain... |
| CVE-2016-4485 | — | — | 4.7% | May 23, 2016 | The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data struct... |
| CVE-2016-4482 | — | — | 0.6% | May 23, 2016 | The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain ... |
| CVE-2016-2190 | — | — | 1.9% | May 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not pro... |
| CVE-2016-2159 | — | — | 1.4% | May 22, 2016 | The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2... |
| CVE-2016-2158 | — | — | 1.7% | May 22, 2016 | lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.... |
| CVE-2016-2157 | — | — | 1.0% | May 22, 2016 | Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x bef... |
| CVE-2016-2156 | — | — | 1.7% | May 22, 2016 | calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0... |
| CVE-2016-2155 | — | — | 1.6% | May 22, 2016 | The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x... |
| CVE-2016-2154 | — | — | 1.7% | May 22, 2016 | admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 do... |
| CVE-2016-2153 | — | — | 1.5% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x befo... |
| CVE-2016-2152 | — | — | 1.5% | May 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2... |
| CVE-2016-2151 | — | — | 1.6% | May 22, 2016 | user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before ... |
| CVE-2016-4567 | — | — | 6.4% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in Word... |
| CVE-2016-4566 | — | — | 5.4% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5... |
| CVE-2016-4544 | CRITICAL | 9.8 | 6.7% | May 22, 2016 | The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now