2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3169 | — | — | 2.2% | Apr 12, 2016 | The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging c... |
| CVE-2016-3168 | — | — | 2.5% | Apr 12, 2016 | The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authenticatio... |
| CVE-2016-3167 | — | — | 1.4% | Apr 12, 2016 | Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allo... |
| CVE-2016-3166 | — | — | 1.2% | Apr 12, 2016 | CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.... |
| CVE-2016-3165 | — | — | 1.4% | Apr 12, 2016 | The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers... |
| CVE-2016-3164 | — | — | 1.9% | Apr 12, 2016 | Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect atta... |
| CVE-2016-3163 | — | — | 1.4% | Apr 12, 2016 | The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct br... |
| CVE-2016-3162 | — | — | 1.6% | Apr 12, 2016 | The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restri... |
| CVE-2016-2558 | HIGH | 8.4 | 0.4% | Apr 12, 2016 | The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 befor... |
| CVE-2016-2557 | HIGH | 8.4 | 0.4% | Apr 12, 2016 | The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 befor... |
| CVE-2016-2556 | HIGH | 7.8 | 0.3% | Apr 12, 2016 | The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 befor... |
| CVE-2016-2170 | CRITICAL | 9.8 | 12.7% | Apr 12, 2016 | Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands vi... |
| CVE-2016-2166 | — | — | 4.3% | Apr 12, 2016 | The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apach... |
| CVE-2016-2140 | — | — | 2.1% | Apr 12, 2016 | The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw... |
| CVE-2016-1866 | — | — | 1.5% | Apr 12, 2016 | Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle atta... |
| CVE-2016-0733 | — | — | 3.1% | Apr 12, 2016 | The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which ... |
| CVE-2016-3987 | CRITICAL | 9.8 | 22.3% | Apr 12, 2016 | The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para... |
| CVE-2016-3986 | — | — | 7.9% | Apr 12, 2016 | Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a... |
| CVE-2016-3985 | — | — | 1.2% | Apr 12, 2016 | The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS... |
| CVE-2016-2857 | HIGH | 8.4 | 0.6% | Apr 12, 2016 | The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (... |
| CVE-2016-1885 | — | — | 1.3% | Apr 12, 2016 | Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 ... |
| CVE-2016-1568 | HIGH | 8.8 | 0.5% | Apr 12, 2016 | Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users... |
| CVE-2016-0735 | — | — | 1.7% | Apr 11, 2016 | Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restr... |
| CVE-2016-3678 | — | — | 1.3% | Apr 11, 2016 | Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers... |
| CVE-2016-3676 | — | — | 0.3% | Apr 11, 2016 | Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now