2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5237 | — | — | 0.8% | Jan 23, 2017 | Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m... |
| CVE-2016-5119 | — | — | 2.3% | Jan 23, 2017 | The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by... |
| CVE-2016-5091 | — | — | 2.6% | Jan 23, 2017 | Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive informatio... |
| CVE-2016-4793 | — | — | 5.1% | Jan 23, 2017 | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head... |
| CVE-2016-4484 | — | — | 0.7% | Jan 23, 2017 | The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain ... |
| CVE-2016-4340 | — | — | 10.1% | Jan 23, 2017 | The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8... |
| CVE-2016-4338 | — | — | 21.1% | Jan 23, 2017 | The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef... |
| CVE-2016-4056 | — | — | 1.1% | Jan 23, 2017 | Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers t... |
| CVE-2016-4010 | — | — | 92.9% | Jan 23, 2017 | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary ... |
| CVE-2016-3177 | — | — | 1.6% | Jan 23, 2017 | Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack... |
| CVE-2016-2783 | — | — | 4.4% | Jan 23, 2017 | Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.... |
| CVE-2016-2242 | — | — | 6.6% | Jan 23, 2017 | Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/... |
| CVE-2016-1925 | — | — | 3.0% | Jan 23, 2017 | Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value fo... |
| CVE-2016-1417 | — | — | 4.4% | Jan 23, 2017 | Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct... |
| CVE-2016-1281 | — | — | 0.8% | Jan 23, 2017 | Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibl... |
| CVE-2016-0769 | — | — | 2.9% | Jan 23, 2017 | Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote adm... |
| CVE-2016-0765 | — | — | 1.8% | Jan 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow r... |
| CVE-2016-9870 | — | — | 0.4% | Jan 23, 2017 | EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1... |
| CVE-2016-8213 | — | — | 1.0% | Jan 23, 2017 | EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.... |
| CVE-2016-10157 | — | — | 2.2% | Jan 23, 2017 | Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete p... |
| CVE-2016-10156 | — | — | 1.2% | Jan 23, 2017 | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim... |
| CVE-2016-10104 | — | — | 0.6% | Jan 23, 2017 | Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set... |
| CVE-2016-10103 | — | — | 0.4% | Jan 23, 2017 | Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute be... |
| CVE-2016-10102 | — | — | 0.4% | Jan 23, 2017 | hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. T... |
| CVE-2016-10101 | — | — | 0.6% | Jan 23, 2017 | Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribu... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now