2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-11077 | LOW | 2.7 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change... |
| CVE-2016-11027 | LOW | 2.4 | 0.1% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximat... |
| CVE-2016-1544 | LOW | 3.3 | 0.9% | Feb 6, 2020 | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion). |
| CVE-2016-6586 | LOW | 3.7 | 1.3% | Jan 8, 2020 | A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a mal... |
| CVE-2016-4980 | LOW | 2.5 | 0.3% | Nov 27, 2019 | A password generation weakness exists in xquest through 2016-06-13. |
| CVE-2016-4983 | LOW | 3.3 | 0.4% | Nov 5, 2019 | A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. |
| CVE-2016-1000002 | LOW | 2.4 | 0.5% | Nov 5, 2019 | gdm3 3.14.2 and possibly later has an information leak before screen lock |
| CVE-2016-1586 | LOW | 1.8 | 0.7% | Apr 22, 2019 | A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for ... |
| CVE-2016-1584 | LOW | 1.6 | 0.9% | Apr 22, 2019 | In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consu... |
| CVE-2016-7061 | LOW | 3.5 | 1.8% | Sep 10, 2018 | An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discover... |
| CVE-2016-0373 | LOW | 3.1 | 0.8% | Aug 30, 2018 | IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST... |
| CVE-2016-0205 | LOW | 3.3 | 0.4% | Aug 30, 2018 | A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacke... |
| CVE-2016-2922 | LOW | 3.7 | 0.7% | Aug 13, 2018 | IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SS... |
| CVE-2016-8609 | LOW | 3.7 | 1.7% | Aug 1, 2018 | It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this ... |
| CVE-2016-9580 | LOW | 3.3 | 2.0% | Aug 1, 2018 | An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow. |
| CVE-2016-8651 | LOW | 3.1 | 1.4% | Aug 1, 2018 | An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manife... |
| CVE-2016-9581 | LOW | 3.3 | 2.0% | Aug 1, 2018 | An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openj... |
| CVE-2016-8623 | LOW | 3.3 | 2.6% | Aug 1, 2018 | A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-afte... |
| CVE-2016-8616 | LOW | 3.7 | 3.5% | Aug 1, 2018 | A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons o... |
| CVE-2016-8617 | LOW | 3.3 | 0.6% | Jul 31, 2018 | The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if ... |
| CVE-2016-8622 | LOW | 3.7 | 4.7% | Jul 31, 2018 | The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if th... |
| CVE-2016-4455 | LOW | 3.3 | 0.4% | Apr 14, 2017 | The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) fo... |
| CVE-2016-9085 | LOW | 3.3 | 0.4% | Feb 3, 2017 | Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors. |
| CVE-2016-8217 | LOW | 3.7 | 1.5% | Feb 3, 2017 | EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could... |
| CVE-2016-9908 | LOW | 3.3 | 0.4% | Dec 23, 2016 | Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. I... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now