6,449 vulnerabilities published in 2016
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the va
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions <
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances cou
A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepo
A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated, remot
In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage)
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by le
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows r
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request request
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege le
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in th
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connecti
In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be t
In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data stru
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the send
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of
The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of se
Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote atta
An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmi
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-li
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. A
An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invok
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements
An issue was discovered in Asterisk Open Source 13.12.x and 13.13.x before 13.13.1 and 14.x before 14.2.1. If an SDP off
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via v
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cau
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers
Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bound
X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving leng
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) X
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service coul
A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Swi
A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticat
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco Fir
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an una
A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an
A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote at
A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could a
A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unau
A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web
An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify an
Adobe ColdFusion Builder versions 2016 update 2 and earlier, 3.0.3 and earlier have an important vulnerability that coul
Adobe Digital Editions versions 4.5.2 and earlier has an issue with parsing crafted XML entries that could lead to infor
The SNAP Lite component in certain SISCO MMS-EASE and AX-S4 ICCP products allows remote attackers to cause a denial of s
Scan for 2016 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started