2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5010 | — | — | 2.1% | Apr 20, 2017 | coders/tiff.c in ImageMagick before 6.9.5-3 allows remote attackers to cause a denial of service (out-of-bounds read) vi... |
| CVE-2016-4862 | — | — | 2.1% | Apr 20, 2017 | Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remot... |
| CVE-2016-4850 | — | — | 2.2% | Apr 20, 2017 | LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code. |
| CVE-2016-4844 | — | — | 1.5% | Apr 20, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks. |
| CVE-2016-4843 | — | — | 1.9% | Apr 20, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information. |
| CVE-2016-4842 | — | — | 1.6% | Apr 20, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read. |
| CVE-2016-4818 | — | — | 0.9% | Apr 20, 2017 | DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for... |
| CVE-2016-1220 | — | — | 1.0% | Apr 20, 2017 | Cybozu Garoon before 4.2.2 does not properly restrict access. |
| CVE-2016-1218 | — | — | 1.5% | Apr 20, 2017 | SQL injection vulnerability in Cybozu Garoon before 4.2.2. |
| CVE-2016-1217 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1216 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1215 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1214 | — | — | 1.2% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1213 | — | — | 1.3% | Apr 20, 2017 | The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. |
| CVE-2016-6347 | — | — | 1.6% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject ... |
| CVE-2016-6341 | — | — | 0.3% | Apr 20, 2017 | oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local ... |
| CVE-2016-6338 | — | — | 0.5% | Apr 20, 2017 | ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, all... |
| CVE-2016-6337 | — | — | 1.2% | Apr 20, 2017 | MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging... |
| CVE-2016-6336 | — | — | 1.0% | Apr 20, 2017 | MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete... |
| CVE-2016-6335 | — | — | 1.7% | Apr 20, 2017 | MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of ... |
| CVE-2016-6334 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x... |
| CVE-2016-6333 | — | — | 1.0% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x bef... |
| CVE-2016-6332 | — | — | 1.5% | Apr 20, 2017 | MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allo... |
| CVE-2016-6331 | — | — | 2.1% | Apr 20, 2017 | ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass i... |
| CVE-2016-5762 | — | — | 5.7% | Apr 20, 2017 | Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remo... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now