2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5016Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 1...
CVE-2016-4313Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra...
CVE-2016-3691Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request met...
CVE-2016-3114Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leve...
CVE-2016-3076Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cau...
CVE-2016-2564Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid func...
CVE-2016-9954The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote ...
CVE-2016-5399HIGH7.8The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attac...
CVE-2016-5168Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain ...
CVE-2016-3702Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext i...
CVE-2016-3109The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
CVE-2016-3067Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain pr...
CVE-2016-2433The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to...
CVE-2016-2347Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote atta...
CVE-2016-2173CRITICAL9.8org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute a...
CVE-2016-1561ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic...
CVE-2016-1560ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and...
CVE-2016-1520The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m...
CVE-2016-1519The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate...
CVE-2016-1518The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP ph...
CVE-2016-1221Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2016-1210The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allo...
CVE-2016-1198Photopt for Android before 2.0.1 does not verify SSL certificates.
CVE-2016-1187Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.
CVE-2016-1186Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now