2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-8721CRITICAL9.1An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A W...
CVE-2016-10328CRITICAL9.8FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser...
CVE-2016-1908CRITICAL9.8The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the loca...
CVE-2016-8735CRITICAL9.8Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8...
CVE-2016-6809CRITICAL9.8Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists bec...
CVE-2016-10229CRITICAL9.8udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an ...
CVE-2016-10307CRITICAL9.8Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root...
CVE-2016-10305CRITICAL9.8Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0...
CVE-2016-10145CRITICAL9.8Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related t...
CVE-2016-10144CRITICAL9.8coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
CVE-2016-10195CRITICAL9.8The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via ...
CVE-2016-9558CRITICAL9.8(1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have uns...
CVE-2016-9400CRITICAL9.8The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to w...
CVE-2016-9053CRITICAL9.8An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Datab...
CVE-2016-9051CRITICAL9.8An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospik...
CVE-2016-9369CRITICAL9.8An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52...
CVE-2016-9366CRITICAL9.8An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52...
CVE-2016-9361CRITICAL9.8An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52...
CVE-2016-9343CRITICAL10An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (exc...
CVE-2016-8567CRITICAL9.8An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the ...
CVE-2016-2148CRITICAL9.8Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecif...
CVE-2016-10150CRITICAL9.8Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4...
CVE-2016-6090CRITICAL9.8IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performi...
CVE-2016-6269CRITICAL9.1Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before bu...
CVE-2016-10182CRITICAL9.8An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now