Skip to main content

Year archive

CVEs published in 2016

Archive summary

6,449 CVEs published in 2016 — 895 Critical, 2,887 High, 2,446 Medium, 221 Low, 0 Unrated.

CVE-2016-2937

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2936

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2935

Published Nov 30, 2016

The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2934

Published Nov 30, 2016

Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2933

Published Nov 30, 2016

Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2932

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2931

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9481

Published Nov 29, 2016

In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9480

Published Nov 29, 2016

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Hea…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1251

Published Nov 29, 2016

There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5393

Published Nov 29, 2016

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9644

Published Nov 28, 2016

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9555

Published Nov 28, 2016

The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a den…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9313

Published Nov 28, 2016

security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9191

Published Nov 28, 2016

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by le…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9178

Published Nov 28, 2016

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9084

Published Nov 28, 2016

drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of service (integer overflow) or have…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9083

Published Nov 28, 2016

drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unsp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8650

Published Nov 28, 2016

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8646

Published Nov 28, 2016

The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel h…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 551-575 of 6,449 CVEsPage 23 of 258