2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1000360Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9847. Reason: This candidate is a reservation ...
CVE-2016-6877Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors...
CVE-2016-9692IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by impro...
CVE-2016-9691IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entit...
CVE-2016-8916IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local...
CVE-2016-0255IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-...
CVE-2016-7055MEDIUM5.9There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1....
CVE-2016-7054In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack b...
CVE-2016-7053In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. T...
CVE-2016-9976IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacke...
CVE-2016-2930IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without a...
CVE-2016-0382The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be...
CVE-2016-10368Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.16239...
CVE-2016-10367In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a ce...
CVE-2016-5810upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive ...
CVE-2016-5063The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta...
CVE-2016-5006The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers ...
CVE-2016-4467The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly veri...
CVE-2016-4442The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocate...
CVE-2016-10243TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands...
CVE-2016-8649lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inh...
CVE-2016-10351Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive ...
CVE-2016-10350The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote ...
CVE-2016-10349The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of servic...
CVE-2016-8593Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now