Skip to main content

Year archive

CVEs published in 2016

Archive summary

6,449 CVEs published in 2016 — 895 Critical, 2,887 High, 2,446 Medium, 221 Low, 0 Unrated.

CVE-2016-8645

Published Nov 28, 2016

The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that make…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8633

Published Nov 28, 2016

drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8632

Published Nov 28, 2016

The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8630

Published Nov 28, 2016

The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8970

Published Nov 28, 2016

crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed,…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1328

Published Nov 28, 2016

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2929

Published Nov 25, 2016

IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2928

Published Nov 25, 2016

IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2927

Published Nov 25, 2016

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic pr…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2926

Published Nov 25, 2016

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational…

CVSS 5.4 · Medium

CVE-2016-0319

Published Nov 25, 2016

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0318

Published Nov 25, 2016

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0317

Published Nov 25, 2016

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0316

Published Nov 25, 2016

Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote au…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9452

Published Nov 25, 2016

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9451

Published Nov 25, 2016

Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9450

Published Nov 25, 2016

The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9449

Published Nov 25, 2016

The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging incons…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6754

Published Nov 25, 2016

A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6753

Published Nov 25, 2016

An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a lo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6752

Published Nov 25, 2016

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 co…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6751

Published Nov 25, 2016

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 co…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6750

Published Nov 25, 2016

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 co…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6749

Published Nov 25, 2016

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 co…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6748

Published Nov 25, 2016

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 co…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 576-600 of 6,449 CVEsPage 24 of 258