2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6726Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.
CVE-2016-4874Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
CVE-2016-4873Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project fun...
CVE-2016-4872Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of u...
CVE-2016-4871Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
CVE-2016-4870Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbi...
CVE-2016-4869Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment vari...
CVE-2016-4868Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email ...
CVE-2016-4867Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized pr...
CVE-2016-4866Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject...
CVE-2016-4865Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject...
CVE-2016-8602The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service...
CVE-2016-7060The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physicall...
CVE-2016-7051HIGH8.6XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allow...
CVE-2016-7032sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via...
CVE-2016-6489HIGH7.5The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channe...
CVE-2016-6299The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privilege...
CVE-2016-5312Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au...
CVE-2016-5310MEDIUM5.5The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); ...
CVE-2016-5309MEDIUM5.5The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); ...
CVE-2016-4890ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for ...
CVE-2016-4889ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leve...
CVE-2016-4888Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inj...
CVE-2016-4875Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBo...
CVE-2016-4455LOW3.3The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) fo...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now