2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5551——Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition)....
CVE-2016-5016——Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 1...
CVE-2016-4313——Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra...
CVE-2016-3691——Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request met...
CVE-2016-3114——Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leve...
CVE-2016-3076——Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cau...
CVE-2016-2564——Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid func...
CVE-2016-9954——The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote ...
CVE-2016-5399HIGH7.8The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attac...
CVE-2016-5168——Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain ...
CVE-2016-3702——Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext i...
CVE-2016-3109——The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
CVE-2016-3067——Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain pr...
CVE-2016-2433——The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to...
CVE-2016-2347——Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote atta...
CVE-2016-2173CRITICAL9.8org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute a...
CVE-2016-1561——ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic...
CVE-2016-1560——ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and...
CVE-2016-1520——The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m...
CVE-2016-1519——The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate...
CVE-2016-1518——The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP ph...
CVE-2016-1221——Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2016-1210——The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allo...
CVE-2016-1198——Photopt for Android before 2.0.1 does not verify SSL certificates.
CVE-2016-1187——Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now