2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5054——OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.
CVE-2016-5053——OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port ...
CVE-2016-5052——OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
CVE-2016-5051——OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data...
CVE-2016-4334MEDIUM6.1Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
CVE-2016-4320——Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a direct...
CVE-2016-4319——Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
CVE-2016-4318——Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CVE-2016-4317——Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CVE-2016-1517——OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
CVE-2016-1516HIGH8.8OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
CVE-2016-7786——Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir...
CVE-2016-6805——Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier ...
CVE-2016-9197——A vulnerability in the CLI command parser of the Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers co...
CVE-2016-9196——A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms c...
CVE-2016-9195——A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) co...
CVE-2016-1000307——Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to in...
CVE-2016-1000306——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1000307. Reason: This candidate is a reservatio...
CVE-2016-8735CRITICAL9.8Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8...
CVE-2016-6809CRITICAL9.8Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists bec...
CVE-2016-5349——The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure ap...
CVE-2016-9219——A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an u...
CVE-2016-9194——A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller ...
CVE-2016-10320——textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be ...
CVE-2016-10319——In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now