2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-5237——Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m...
CVE-2016-5119——The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by...
CVE-2016-5091——Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive informatio...
CVE-2016-4793——The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head...
CVE-2016-4484——The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain ...
CVE-2016-4340——The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8...
CVE-2016-4338——The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef...
CVE-2016-4056——Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers t...
CVE-2016-4010——Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary ...
CVE-2016-3177——Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack...
CVE-2016-2783——Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0....
CVE-2016-2242——Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/...
CVE-2016-1925——Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value fo...
CVE-2016-1417——Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct...
CVE-2016-1281——Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibl...
CVE-2016-0769——Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote adm...
CVE-2016-0765——Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow r...
CVE-2016-9870——EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1...
CVE-2016-8213——EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6....
CVE-2016-10157——Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete p...
CVE-2016-10156——A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim...
CVE-2016-10104——Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set...
CVE-2016-10103——Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute be...
CVE-2016-10102——hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and Encryption profile passwords. T...
CVE-2016-10101——Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribu...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now