2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4931——XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
CVE-2016-4930——Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive informa...
CVE-2016-4929——Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
CVE-2016-4928——Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain adminis...
CVE-2016-4927——Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a...
CVE-2016-4926——Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to ...
CVE-2016-6816——The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0....
CVE-2016-9697——An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking At...
CVE-2016-9696——IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, w...
CVE-2016-9694——IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2016-9165——The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified...
CVE-2016-8973——IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload in...
CVE-2016-5857——The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the k...
CVE-2016-2981——An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user crede...
CVE-2016-2406——The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote au...
CVE-2016-10214——Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to c...
CVE-2016-8855——Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience...
CVE-2016-10253——An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap ...
CVE-2016-10187——The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with Ja...
CVE-2016-0770——Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin...
CVE-2016-10247MEDIUM5.5Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allo...
CVE-2016-10246MEDIUM5.5Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows rem...
CVE-2016-5239——The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute a...
CVE-2016-7955——The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5...
CVE-2016-7103MEDIUM6.1Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now