2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6726 | — | — | 0.8% | Apr 17, 2017 | Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices. |
| CVE-2016-4874 | — | — | 1.0% | Apr 17, 2017 | Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack. |
| CVE-2016-4873 | — | — | 1.2% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project fun... |
| CVE-2016-4872 | — | — | 1.4% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of u... |
| CVE-2016-4871 | — | — | 2.3% | Apr 17, 2017 | Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service. |
| CVE-2016-4870 | — | — | 1.0% | Apr 17, 2017 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbi... |
| CVE-2016-4869 | — | — | 2.0% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment vari... |
| CVE-2016-4868 | — | — | 1.5% | Apr 17, 2017 | Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email ... |
| CVE-2016-4867 | — | — | 1.4% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized pr... |
| CVE-2016-4866 | — | — | 0.8% | Apr 17, 2017 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject... |
| CVE-2016-4865 | — | — | 0.8% | Apr 17, 2017 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject... |
| CVE-2016-8602 | — | — | 3.2% | Apr 14, 2017 | The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service... |
| CVE-2016-7060 | — | — | 0.4% | Apr 14, 2017 | The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physicall... |
| CVE-2016-7051 | HIGH | 8.6 | 2.4% | Apr 14, 2017 | XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allow... |
| CVE-2016-7032 | — | — | 0.3% | Apr 14, 2017 | sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via... |
| CVE-2016-6489 | HIGH | 7.5 | 5.0% | Apr 14, 2017 | The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channe... |
| CVE-2016-6299 | — | — | 1.7% | Apr 14, 2017 | The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privilege... |
| CVE-2016-5312 | — | — | 53.7% | Apr 14, 2017 | Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au... |
| CVE-2016-5310 | MEDIUM | 5.5 | 5.3% | Apr 14, 2017 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); ... |
| CVE-2016-5309 | MEDIUM | 5.5 | 6.9% | Apr 14, 2017 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); ... |
| CVE-2016-4890 | — | — | 3.5% | Apr 14, 2017 | ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for ... |
| CVE-2016-4889 | — | — | 2.7% | Apr 14, 2017 | ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leve... |
| CVE-2016-4888 | — | — | 1.9% | Apr 14, 2017 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inj... |
| CVE-2016-4875 | — | — | 1.7% | Apr 14, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBo... |
| CVE-2016-4455 | LOW | 3.3 | 0.4% | Apr 14, 2017 | The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) fo... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now