2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-7467The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML...
CVE-2016-6811In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user...
CVE-2016-10259Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-o...
CVE-2016-8237Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitra...
CVE-2016-8235Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows loca...
CVE-2016-10323Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synoph...
CVE-2016-10322Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell m...
CVE-2016-6879The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified im...
CVE-2016-6878The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to ...
CVE-2016-10311Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by ...
CVE-2016-10310Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remo...
CVE-2016-6605Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
CVE-2016-10321web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker ...
CVE-2016-6534Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script....
CVE-2016-5642Opmantek NMIS before 8.5.12G has XSS via SNMP.
CVE-2016-5078Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
CVE-2016-5077Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
CVE-2016-5076CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.d...
CVE-2016-5075CloudView NMS before 2.10a has XSS via a TELNET login.
CVE-2016-5074CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
CVE-2016-5073CloudView NMS before 2.10a has XSS via SNMP.
CVE-2016-5072OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser c...
CVE-2016-5071Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.
CVE-2016-5070Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.
CVE-2016-5069Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now