2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9469 | — | — | 2.4% | Mar 28, 2017 | Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all I... |
| CVE-2016-9468 | — | — | 2.1% | Mar 28, 2017 | Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the d... |
| CVE-2016-9467 | — | — | 3.0% | Mar 28, 2017 | Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the f... |
| CVE-2016-9466 | — | — | 1.7% | Mar 28, 2017 | Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery applica... |
| CVE-2016-9465 | — | — | 1.1% | Mar 28, 2017 | Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. ... |
| CVE-2016-9464 | — | — | 1.6% | Mar 28, 2017 | Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing B... |
| CVE-2016-9463 | — | — | 4.1% | Mar 28, 2017 | Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authenti... |
| CVE-2016-9462 | — | — | 1.9% | Mar 28, 2017 | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restori... |
| CVE-2016-9461 | — | — | 2.0% | Mar 28, 2017 | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDA... |
| CVE-2016-9460 | — | — | 1.7% | Mar 28, 2017 | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files a... |
| CVE-2016-9459 | — | — | 1.5% | Mar 28, 2017 | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentiall... |
| CVE-2016-9457 | — | — | 1.5% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Reflected XSS. `www/admin/stats.php` is vulnerable to reflected XSS attacks vi... |
| CVE-2016-9456 | — | — | 0.5% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a securi... |
| CVE-2016-9455 | — | — | 0.8% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's us... |
| CVE-2016-9454 | — | — | 1.1% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver us... |
| CVE-2016-9130 | — | — | 0.9% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver us... |
| CVE-2016-9129 | — | — | 1.4% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or n... |
| CVE-2016-9128 | — | — | 1.6% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to ... |
| CVE-2016-9127 | — | — | 0.8% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserv... |
| CVE-2016-9126 | — | — | 1.4% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit... |
| CVE-2016-9125 | — | — | 2.7% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, ... |
| CVE-2016-9124 | — | — | 2.2% | Mar 28, 2017 | Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of R... |
| CVE-2016-9123 | — | — | 2.1% | Mar 28, 2017 | go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to... |
| CVE-2016-9122 | — | — | 2.0% | Mar 28, 2017 | go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple ... |
| CVE-2016-9121 | — | — | 1.4% | Mar 28, 2017 | go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using EC... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now