2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2530 | — | — | 2.7% | Feb 28, 2016 | The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.1... |
| CVE-2016-2529 | — | — | 1.2% | Feb 28, 2016 | The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 doe... |
| CVE-2016-2528 | — | — | 2.2% | Feb 28, 2016 | The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 ... |
| CVE-2016-2527 | — | — | 1.4% | Feb 28, 2016 | wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure t... |
| CVE-2016-2526 | — | — | 2.0% | Feb 28, 2016 | epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type,... |
| CVE-2016-2525 | — | — | 3.1% | Feb 28, 2016 | epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of head... |
| CVE-2016-2524 | — | — | 1.9% | Feb 28, 2016 | epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, wh... |
| CVE-2016-2523 | — | — | 3.1% | Feb 28, 2016 | The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.1... |
| CVE-2016-2522 | — | — | 2.1% | Feb 28, 2016 | The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2... |
| CVE-2016-2521 | — | — | 0.4% | Feb 28, 2016 | Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.... |
| CVE-2016-2777 | — | — | — | Feb 27, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1868. Reason: This candidate is a reservation du... |
| CVE-2016-2572 | — | — | 10.2% | Feb 27, 2016 | http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote H... |
| CVE-2016-2571 | — | — | 9.4% | Feb 27, 2016 | http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsi... |
| CVE-2016-2570 | — | — | 9.0% | Feb 27, 2016 | The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during ... |
| CVE-2016-2569 | — | — | 31.4% | Feb 27, 2016 | Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote server... |
| CVE-2016-7575 | — | — | — | Feb 26, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7575. Reason: This candidate is a duplicate of... |
| CVE-2016-1342 | — | — | 1.1% | Feb 26, 2016 | The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potenti... |
| CVE-2016-1297 | — | — | 2.8% | Feb 26, 2016 | The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated user... |
| CVE-2016-0763 | — | — | 11.3% | Feb 25, 2016 | The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.... |
| CVE-2016-0714 | — | — | 13.1% | Feb 25, 2016 | The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x... |
| CVE-2016-0706 | — | — | 6.2% | Feb 25, 2016 | Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache... |
| CVE-2016-2542 | HIGH | 7.8 | 0.5% | Feb 24, 2016 | Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via ... |
| CVE-2016-1341 | — | — | 1.1% | Feb 24, 2016 | Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, w... |
| CVE-2016-2537 | — | — | 1.8% | Feb 23, 2016 | The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, whic... |
| CVE-2016-1157 | — | — | 1.0% | Feb 23, 2016 | Cross-site scripting (XSS) vulnerability in log_chat.cgi in Script* Log-Chat before 2.0 allows remote attackers to injec... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now