2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10326 | — | — | 1.5% | Apr 13, 2017 | In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() func... |
| CVE-2016-10325 | — | — | 1.5% | Apr 13, 2017 | In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() ... |
| CVE-2016-10324 | — | — | 2.0% | Apr 13, 2017 | In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function... |
| CVE-2016-6143 | — | — | 3.6% | Apr 13, 2017 | SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, ak... |
| CVE-2016-4800 | — | — | 6.4% | Apr 13, 2017 | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote atta... |
| CVE-2016-4068 | — | — | 2.5% | Apr 13, 2017 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attacker... |
| CVE-2016-3106 | — | — | 0.9% | Apr 13, 2017 | Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner. |
| CVE-2016-2555 | — | — | 79.6% | Apr 13, 2017 | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi... |
| CVE-2016-2104 | — | — | 1.2% | Apr 13, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary we... |
| CVE-2016-1915 | — | — | 4.0% | Apr 13, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 ... |
| CVE-2016-1914 | — | — | 4.1% | Apr 13, 2017 | Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server... |
| CVE-2016-1132 | — | — | 0.7% | Apr 13, 2017 | Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates. |
| CVE-2016-10123 | — | — | 0.4% | Apr 13, 2017 | Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. |
| CVE-2016-10122 | — | — | 0.4% | Apr 13, 2017 | Firejail does not properly clean environment variables, which allows local users to gain privileges. |
| CVE-2016-10121 | — | — | 0.4% | Apr 13, 2017 | Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileg... |
| CVE-2016-10120 | — | — | 0.4% | Apr 13, 2017 | Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local ... |
| CVE-2016-10119 | — | — | 0.4% | Apr 13, 2017 | Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. |
| CVE-2016-10118 | — | — | 0.3% | Apr 13, 2017 | Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /. |
| CVE-2016-10117 | — | — | 0.4% | Apr 13, 2017 | Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting o... |
| CVE-2016-6348 | — | — | 1.3% | Apr 12, 2017 | JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack. |
| CVE-2016-5856 | — | — | 0.6% | Apr 12, 2017 | Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privil... |
| CVE-2016-5313 | — | — | 4.6% | Apr 12, 2017 | Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands. |
| CVE-2016-4897 | — | — | 1.1% | Apr 12, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search... |
| CVE-2016-4896 | — | — | 1.3% | Apr 12, 2017 | SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthoriz... |
| CVE-2016-4895 | — | — | 2.0% | Apr 12, 2017 | SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now