2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5761 | — | — | 1.3% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote att... |
| CVE-2016-5760 | — | — | 1.3% | Apr 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Serv... |
| CVE-2016-5409 | — | — | 1.3% | Apr 20, 2017 | Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which ma... |
| CVE-2016-4849 | — | — | 1.3% | Apr 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbi... |
| CVE-2016-4847 | — | — | 1.3% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject... |
| CVE-2016-4650 | — | — | 2.0% | Apr 20, 2017 | Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows a... |
| CVE-2016-4293 | — | — | 3.6% | Apr 20, 2017 | Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle function... |
| CVE-2016-1219 | — | — | 3.3% | Apr 20, 2017 | Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. |
| CVE-2016-7537 | MEDIUM | 6.5 | 3.3% | Apr 19, 2017 | MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a cra... |
| CVE-2016-7533 | MEDIUM | 6.5 | 2.9% | Apr 19, 2017 | The ReadWPGImage function in coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bo... |
| CVE-2016-7531 | MEDIUM | 6.5 | 2.9% | Apr 19, 2017 | MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a craf... |
| CVE-2016-7529 | MEDIUM | 6.5 | 3.0% | Apr 19, 2017 | coders/xcf.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted XCF ... |
| CVE-2016-7528 | MEDIUM | 6.5 | 2.9% | Apr 19, 2017 | The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (segment... |
| CVE-2016-7522 | MEDIUM | 6.5 | 2.9% | Apr 19, 2017 | The ReadPSDImage function in MagickCore/locale.c in ImageMagick allows remote attackers to cause a denial of service (ou... |
| CVE-2016-7519 | MEDIUM | 6.5 | 2.9% | Apr 19, 2017 | The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bo... |
| CVE-2016-7515 | MEDIUM | 6.5 | 2.9% | Apr 19, 2017 | The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bo... |
| CVE-2016-5410 | — | — | 0.4% | Apr 19, 2017 | firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations ... |
| CVE-2016-10345 | — | — | 0.5% | Apr 18, 2017 | In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which... |
| CVE-2016-3038 | — | — | 0.5% | Apr 17, 2017 | IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2016-3037 | — | — | 0.9% | Apr 17, 2017 | IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticat... |
| CVE-2016-3036 | — | — | 1.7% | Apr 17, 2017 | IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing ... |
| CVE-2016-0228 | — | — | 0.6% | Apr 17, 2017 | IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulner... |
| CVE-2016-5396 | — | — | 2.9% | Apr 17, 2017 | Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. |
| CVE-2016-7551 | — | — | 5.5% | Apr 17, 2017 | chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 an... |
| CVE-2016-6727 | — | — | 2.7% | Apr 17, 2017 | The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now