2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0705 | — | — | 26.3% | Mar 3, 2016 | Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1... |
| CVE-2016-0702 | MEDIUM | 5.1 | 1.9% | Mar 3, 2016 | The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g... |
| CVE-2016-1355 | — | — | 0.8% | Mar 3, 2016 | Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT Syst... |
| CVE-2016-1354 | — | — | 0.8% | Mar 3, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows r... |
| CVE-2016-1329 | — | — | 3.7% | Mar 3, 2016 | Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on... |
| CVE-2016-8000 | — | — | — | Mar 3, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0800. Reason: This candidate is a duplicate of... |
| CVE-2016-2279 | MEDIUM | 6.1 | 7.5% | Mar 2, 2016 | Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef... |
| CVE-2016-2278 | — | — | 13.4% | Mar 2, 2016 | Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows... |
| CVE-2016-0704 | — | — | 6.9% | Mar 2, 2016 | An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL... |
| CVE-2016-0703 | — | — | 5.4% | Mar 2, 2016 | The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.... |
| CVE-2016-0800 | — | — | 82.1% | Mar 1, 2016 | The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to se... |
| CVE-2016-2562 | — | — | 0.8% | Mar 1, 2016 | The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificat... |
| CVE-2016-2561 | — | — | 2.5% | Mar 1, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow r... |
| CVE-2016-2560 | — | — | 3.1% | Mar 1, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5... |
| CVE-2016-2559 | — | — | 1.7% | Mar 1, 2016 | Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL p... |
| CVE-2016-1353 | — | — | 1.7% | Mar 1, 2016 | The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), an... |
| CVE-2016-0245 | — | — | 1.0% | Feb 29, 2016 | The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticat... |
| CVE-2016-0244 | — | — | 0.8% | Feb 29, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 C... |
| CVE-2016-0243 | — | — | 1.0% | Feb 29, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 C... |
| CVE-2016-0225 | — | — | 1.1% | Feb 29, 2016 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator adm... |
| CVE-2016-0216 | — | — | 2.4% | Feb 29, 2016 | Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attacker... |
| CVE-2016-0213 | — | — | 2.4% | Feb 29, 2016 | Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attacker... |
| CVE-2016-0212 | — | — | 2.5% | Feb 29, 2016 | Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attacker... |
| CVE-2016-2532 | — | — | 2.5% | Feb 28, 2016 | The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1... |
| CVE-2016-2531 | — | — | 2.5% | Feb 28, 2016 | Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x befor... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now