2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3017 | — | — | 2.2% | Feb 1, 2017 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security miscon... |
| CVE-2016-3016 | — | — | 0.4% | Feb 1, 2017 | IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying th... |
| CVE-2016-2987 | — | — | 0.8% | Feb 1, 2017 | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to ... |
| CVE-2016-2939 | — | — | 1.0% | Feb 1, 2017 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ... |
| CVE-2016-2938 | — | — | 1.0% | Feb 1, 2017 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ... |
| CVE-2016-2908 | — | — | 3.4% | Feb 1, 2017 | IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external e... |
| CVE-2016-0396 | — | — | 1.2% | Feb 1, 2017 | IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed wit... |
| CVE-2016-0394 | — | — | 0.3% | Feb 1, 2017 | IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attac... |
| CVE-2016-0297 | — | — | 0.9% | Feb 1, 2017 | IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive informati... |
| CVE-2016-0296 | — | — | 0.3% | Feb 1, 2017 | IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that ... |
| CVE-2016-0265 | — | — | 0.7% | Feb 1, 2017 | IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attac... |
| CVE-2016-9225 | — | — | 2.7% | Feb 1, 2017 | A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Se... |
| CVE-2016-10079 | — | — | 6.5% | Feb 1, 2017 | SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long... |
| CVE-2016-8491 | — | — | 1.5% | Feb 1, 2017 | The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write a... |
| CVE-2016-9963 | — | — | 3.1% | Feb 1, 2017 | Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files ... |
| CVE-2016-4038 | — | — | 0.4% | Feb 1, 2017 | Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/... |
| CVE-2016-10173 | — | — | 4.7% | Feb 1, 2017 | Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote at... |
| CVE-2016-10164 | — | — | 7.5% | Feb 1, 2017 | Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform,... |
| CVE-2016-9962 | — | — | 0.4% | Jan 31, 2017 | RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows th... |
| CVE-2016-9421 | — | — | 1.3% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) be... |
| CVE-2016-9420 | — | — | 2.6% | Jan 31, 2017 | MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified im... |
| CVE-2016-9419 | — | — | 1.0% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB ... |
| CVE-2016-9418 | — | — | 2.3% | Jan 31, 2017 | MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote atta... |
| CVE-2016-9417 | — | — | 1.7% | Jan 31, 2017 | The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remo... |
| CVE-2016-9416 | — | — | 2.1% | Jan 31, 2017 | SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System b... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now