2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-3955CRITICAL9.8The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attacke...
CVE-2016-2141CRITICAL9.8It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cl...
CVE-2016-4171CRITICAL9.8Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code...
CVE-2016-4163CRITICAL9.8Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621...
CVE-2016-4162CRITICAL9.8Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621...
CVE-2016-4161CRITICAL9.8Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621...
CVE-2016-4160CRITICAL9.8Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621...
CVE-2016-4138CRITICAL9.8Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof...
CVE-2016-4121CRITICAL9.8Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows ...
CVE-2016-4120CRITICAL9.8Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621...
CVE-2016-2496CRITICAL9.8The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjackin...
CVE-2016-5118CRITICAL9.8The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbit...
CVE-2016-3720CRITICAL9.8XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xm...
CVE-2016-2786CRITICAL9.8The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not prope...
CVE-2016-2785CRITICAL9.8Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow...
CVE-2016-4448CRITICAL9.8Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specif...
CVE-2016-2310CRITICAL9.8General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000,...
CVE-2016-4437CRITICAL9.8Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack...
CVE-2016-4432CRITICAL9.1The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to b...
CVE-2016-3088CRITICAL9.8The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr...
CVE-2016-0718CRITICAL9.8Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a m...
CVE-2016-4544CRITICAL9.8The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0....
CVE-2016-4346CRITICAL9.8Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a...
CVE-2016-4345CRITICAL9.8Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows rem...
CVE-2016-4344CRITICAL9.8Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now