2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-11055MEDIUM4.3Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 befor...
CVE-2016-11040MEDIUM4.6An issue was discovered on Samsung mobile devices with L(5.0/5.1) (with USB OTG MyFile2014_L_ESS support) software. Ther...
CVE-2016-11035MEDIUM5.5An issue was discovered on Samsung mobile devices with software through 2016-05-27 (Exynos AP chipsets). A local graphic...
CVE-2016-11034MEDIUM6.5An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Q...
CVE-2016-11032MEDIUM5.3An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality ...
CVE-2016-11053MEDIUM4.6An issue was discovered on Samsung mobile devices with software through 2015-11-11 (supporting FRP/RL). There is a Facto...
CVE-2016-11050MEDIUM4.3An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attack...
CVE-2016-11048MEDIUM4.6An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a ...
CVE-2016-11041MEDIUM4.6An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending ...
CVE-2016-1000111MEDIUM5.3Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not pro...
CVE-2016-1159MEDIUM6.5In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain...
CVE-2016-3182MEDIUM5.5The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of ser...
CVE-2016-1000109MEDIUM5.3HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicat...
CVE-2016-5710MEDIUM4.6NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspeci...
CVE-2016-7524MEDIUM6.5coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil...
CVE-2016-7523MEDIUM6.5coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil...
CVE-2016-1000237MEDIUM6.1sanitize-html before 1.4.3 has XSS.
CVE-2016-6585MEDIUM5.3A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a...
CVE-2016-5346MEDIUM5.5An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointe...
CVE-2016-6587MEDIUM5.5An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Secur...
CVE-2016-6588MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management...
CVE-2016-6589MEDIUM6.5A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Sui...
CVE-2016-1000029MEDIUM4.8Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would po...
CVE-2016-1000028MEDIUM4.8Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would on...
CVE-2016-1000229MEDIUM6.1swagger-ui has XSS in key names

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now