2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2143 | HIGH | 7.8 | 0.6% | Apr 27, 2016 | The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, ... |
| CVE-2016-2085 | — | — | 0.4% | Apr 27, 2016 | The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy ... |
| CVE-2016-2069 | — | — | 0.3% | Apr 27, 2016 | Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering... |
| CVE-2016-0774 | — | — | 0.3% | Apr 27, 2016 | The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux packag... |
| CVE-2016-4002 | CRITICAL | 9.8 | 6.4% | Apr 26, 2016 | Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept ... |
| CVE-2016-3082 | — | — | 20.8% | Apr 26, 2016 | XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote at... |
| CVE-2016-3081 | — | — | 94.2% | Apr 26, 2016 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a... |
| CVE-2016-3074 | CRITICAL | 9.8 | 37.0% | Apr 26, 2016 | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of... |
| CVE-2016-1601 | — | — | 2.5% | Apr 26, 2016 | yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/... |
| CVE-2016-2346 | — | — | 0.9% | Apr 25, 2016 | Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-t... |
| CVE-2016-2333 | — | — | 0.8% | Apr 25, 2016 | SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encry... |
| CVE-2016-2332 | — | — | 2.8% | Apr 25, 2016 | flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01... |
| CVE-2016-2331 | — | — | 2.5% | Apr 25, 2016 | The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a d... |
| CVE-2016-1202 | — | — | 0.4% | Apr 25, 2016 | Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan ho... |
| CVE-2016-1185 | — | — | 0.7% | Apr 25, 2016 | The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token ... |
| CVE-2016-4054 | — | — | 74.0% | Apr 25, 2016 | Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via cr... |
| CVE-2016-4053 | — | — | 11.4% | Apr 25, 2016 | Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via cra... |
| CVE-2016-4052 | — | — | 10.2% | Apr 25, 2016 | Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause... |
| CVE-2016-4051 | — | — | 16.8% | Apr 25, 2016 | Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to ca... |
| CVE-2016-4085 | — | — | 3.0% | Apr 25, 2016 | Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.1... |
| CVE-2016-4084 | — | — | 1.8% | Apr 25, 2016 | Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 allow... |
| CVE-2016-4083 | — | — | 1.8% | Apr 25, 2016 | epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is avai... |
| CVE-2016-4082 | — | — | 2.4% | Apr 25, 2016 | epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 us... |
| CVE-2016-4081 | — | — | 2.0% | Apr 25, 2016 | epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an in... |
| CVE-2016-4080 | — | — | 2.1% | Apr 25, 2016 | epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 misparses ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now