2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1000360 | — | — | — | May 7, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9847. Reason: This candidate is a reservation ... |
| CVE-2016-6877 | — | — | 1.3% | May 5, 2017 | Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors... |
| CVE-2016-9692 | — | — | 1.6% | May 5, 2017 | IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by impro... |
| CVE-2016-9691 | — | — | 1.4% | May 5, 2017 | IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entit... |
| CVE-2016-8916 | — | — | 0.3% | May 5, 2017 | IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local... |
| CVE-2016-0255 | — | — | 0.9% | May 5, 2017 | IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-... |
| CVE-2016-7055 | MEDIUM | 5.9 | 14.3% | May 4, 2017 | There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.... |
| CVE-2016-7054 | — | — | 31.9% | May 4, 2017 | In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack b... |
| CVE-2016-7053 | — | — | 21.3% | May 4, 2017 | In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. T... |
| CVE-2016-9976 | — | — | 1.7% | May 3, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacke... |
| CVE-2016-2930 | — | — | 1.6% | May 3, 2017 | IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without a... |
| CVE-2016-0382 | — | — | 0.3% | May 3, 2017 | The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be... |
| CVE-2016-10368 | — | — | 2.2% | May 3, 2017 | Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.16239... |
| CVE-2016-10367 | — | — | 16.1% | May 3, 2017 | In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a ce... |
| CVE-2016-5810 | — | — | 15.4% | May 2, 2017 | upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive ... |
| CVE-2016-5063 | — | — | 8.4% | May 2, 2017 | The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta... |
| CVE-2016-5006 | — | — | 1.1% | May 2, 2017 | The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers ... |
| CVE-2016-4467 | — | — | 1.6% | May 2, 2017 | The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly veri... |
| CVE-2016-4442 | — | — | 1.6% | May 2, 2017 | The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocate... |
| CVE-2016-10243 | — | — | 7.1% | May 2, 2017 | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands... |
| CVE-2016-8649 | — | — | 2.8% | May 1, 2017 | lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inh... |
| CVE-2016-10351 | — | — | 0.4% | May 1, 2017 | Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive ... |
| CVE-2016-10350 | — | — | 1.6% | May 1, 2017 | The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote ... |
| CVE-2016-10349 | — | — | 1.7% | May 1, 2017 | The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of servic... |
| CVE-2016-8593 | — | — | 7.0% | Apr 28, 2017 | Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now