2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6095 | — | — | 1.6% | Feb 2, 2017 | IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attack... |
| CVE-2016-5935 | — | — | 0.7% | Feb 2, 2017 | IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to ... |
| CVE-2016-6238 | — | — | 0.9% | Feb 2, 2017 | The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (... |
| CVE-2016-6237 | — | — | 0.9% | Feb 2, 2017 | The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of serv... |
| CVE-2016-6236 | — | — | 0.9% | Feb 2, 2017 | The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of ... |
| CVE-2016-6235 | — | — | 0.9% | Feb 2, 2017 | The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of ... |
| CVE-2016-6234 | — | — | 0.9% | Feb 2, 2017 | The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of servi... |
| CVE-2016-1566 | — | — | 2.2% | Feb 2, 2017 | Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled... |
| CVE-2016-9739 | — | — | 0.4% | Feb 1, 2017 | IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a lo... |
| CVE-2016-9704 | — | — | 1.0% | Feb 1, 2017 | IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2016-9703 | — | — | 0.3% | Feb 1, 2017 | IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized use... |
| CVE-2016-9008 | — | — | 1.0% | Feb 1, 2017 | IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugin... |
| CVE-2016-9000 | — | — | 1.1% | Feb 1, 2017 | IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote... |
| CVE-2016-8999 | — | — | 0.7% | Feb 1, 2017 | IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to rend... |
| CVE-2016-8982 | — | — | 1.3% | Feb 1, 2017 | IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosur... |
| CVE-2016-8977 | — | — | 1.1% | Feb 1, 2017 | IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This infor... |
| CVE-2016-8963 | — | — | 0.3% | Feb 1, 2017 | IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. |
| CVE-2016-8938 | — | — | 2.8% | Feb 1, 2017 | IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on... |
| CVE-2016-8933 | — | — | 1.8% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp... |
| CVE-2016-8932 | — | — | 1.9% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu... |
| CVE-2016-8931 | — | — | 1.9% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu... |
| CVE-2016-8930 | — | — | 1.0% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-8929 | — | — | 0.9% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-8928 | — | — | 1.0% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-8919 | — | — | 2.8% | Feb 1, 2017 | IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from un... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now