2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5016 | — | — | 1.0% | Apr 24, 2017 | Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 1... |
| CVE-2016-4313 | — | — | 8.7% | Apr 24, 2017 | Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra... |
| CVE-2016-3691 | — | — | 0.6% | Apr 24, 2017 | Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request met... |
| CVE-2016-3114 | — | — | 0.9% | Apr 24, 2017 | Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leve... |
| CVE-2016-3076 | — | — | 2.6% | Apr 24, 2017 | Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cau... |
| CVE-2016-2564 | — | — | 1.3% | Apr 23, 2017 | Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid func... |
| CVE-2016-9954 | — | — | 2.4% | Apr 21, 2017 | The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote ... |
| CVE-2016-5399 | HIGH | 7.8 | 9.8% | Apr 21, 2017 | The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attac... |
| CVE-2016-5168 | — | — | 1.7% | Apr 21, 2017 | Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain ... |
| CVE-2016-3702 | — | — | 1.2% | Apr 21, 2017 | Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext i... |
| CVE-2016-3109 | — | — | 28.2% | Apr 21, 2017 | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. |
| CVE-2016-3067 | — | — | 2.0% | Apr 21, 2017 | Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain pr... |
| CVE-2016-2433 | — | — | 0.7% | Apr 21, 2017 | The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to... |
| CVE-2016-2347 | — | — | 3.2% | Apr 21, 2017 | Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote atta... |
| CVE-2016-2173 | CRITICAL | 9.8 | 6.3% | Apr 21, 2017 | org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute a... |
| CVE-2016-1561 | — | — | 74.3% | Apr 21, 2017 | ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic... |
| CVE-2016-1560 | — | — | 72.3% | Apr 21, 2017 | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and... |
| CVE-2016-1520 | — | — | 2.2% | Apr 21, 2017 | The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m... |
| CVE-2016-1519 | — | — | 1.0% | Apr 21, 2017 | The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate... |
| CVE-2016-1518 | — | — | 1.7% | Apr 21, 2017 | The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP ph... |
| CVE-2016-1221 | — | — | 0.6% | Apr 21, 2017 | Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att... |
| CVE-2016-1210 | — | — | 0.6% | Apr 21, 2017 | The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allo... |
| CVE-2016-1198 | — | — | 0.8% | Apr 21, 2017 | Photopt for Android before 2.0.1 does not verify SSL certificates. |
| CVE-2016-1187 | — | — | 1.2% | Apr 21, 2017 | Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates. |
| CVE-2016-1186 | — | — | 0.9% | Apr 21, 2017 | Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now