2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5726 | — | — | 1.6% | Feb 9, 2017 | Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and exec... |
| CVE-2016-3102 | — | — | 1.7% | Feb 9, 2017 | The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection m... |
| CVE-2016-10199 | — | — | 4.2% | Feb 9, 2017 | The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remo... |
| CVE-2016-10198 | — | — | 2.7% | Feb 9, 2017 | The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3... |
| CVE-2016-10192 | — | — | 6.2% | Feb 9, 2017 | Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x befo... |
| CVE-2016-10191 | — | — | 7.5% | Feb 9, 2017 | Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and... |
| CVE-2016-10190 | — | — | 8.4% | Feb 9, 2017 | Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.... |
| CVE-2016-9686 | — | — | 1.3% | Feb 8, 2017 | The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this t... |
| CVE-2016-9005 | — | — | 1.8% | Feb 8, 2017 | IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to... |
| CVE-2016-8954 | — | — | 2.4% | Feb 8, 2017 | IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container o... |
| CVE-2016-5934 | — | — | 1.0% | Feb 8, 2017 | IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By ... |
| CVE-2016-5918 | — | — | 0.3% | Feb 8, 2017 | IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace o... |
| CVE-2016-5902 | — | — | 0.9% | Feb 8, 2017 | IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2016-5900 | — | — | 0.9% | Feb 8, 2017 | IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive inform... |
| CVE-2016-0310 | — | — | 0.5% | Feb 8, 2017 | IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to th... |
| CVE-2016-0308 | — | — | 0.7% | Feb 8, 2017 | IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of i... |
| CVE-2016-0307 | — | — | 1.2% | Feb 8, 2017 | IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in retur... |
| CVE-2016-0305 | — | — | 0.7% | Feb 8, 2017 | IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote at... |
| CVE-2016-0214 | — | — | 1.4% | Feb 8, 2017 | IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit thi... |
| CVE-2016-0210 | — | — | 1.7% | Feb 8, 2017 | IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing ... |
| CVE-2016-0206 | — | — | 0.3% | Feb 8, 2017 | IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of... |
| CVE-2016-0203 | — | — | 0.4% | Feb 8, 2017 | A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated us... |
| CVE-2016-0202 | — | — | 0.3% | Feb 8, 2017 | A vulnerability has been identified in tasks, backend object generated for handling any action performed by the applicat... |
| CVE-2016-9748 | — | — | 0.9% | Feb 8, 2017 | IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be ... |
| CVE-2016-6032 | — | — | 0.6% | Feb 8, 2017 | IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now