Skip to main content

Daily materialized evidence profile

Year 2016

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
6,449
CVEs with mentions
975
Total mentions
1,799
CVEs with KEV
53
CVEs with PoC
1

Attack vector counts

Network
4,576
Adjacent network
60
Local
1,760
Physical
53

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2016-3088

Published Jun 1, 2016

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
72.7
KEV listed

CVE-2016-5195

Published Nov 10, 2016

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature…

CVSS 7.0 · High
evidence mentions
31
Buzz score
72.5
KEV listed

CVE-2016-4117

Published May 11, 2016

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

CVSS 9.8 · Critical
evidence mentions
56
Buzz score
71.0
KEV listed

CVE-2016-1019

Published Apr 7, 2016

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as e…

CVSS 9.8 · Critical
evidence mentions
28
Buzz score
71.0
KEV listed

CVE-2016-0189

Published May 11, 2016

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code…

CVSS 7.5 · High
evidence mentions
48
Buzz score
69.5
KEV listed