2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2403——Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty p...
CVE-2016-1894——NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vecto...
CVE-2016-1502——NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and dele...
CVE-2016-6104——IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the imp...
CVE-2016-6097——IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another ...
CVE-2016-6096——IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows us...
CVE-2016-6094——IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information abou...
CVE-2016-6092——IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by...
CVE-2016-3020——IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restriction...
CVE-2016-7400——Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm...
CVE-2016-7164——The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segm...
CVE-2016-6199——ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized objec...
CVE-2016-6175——Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via...
CVE-2016-6131——The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and ...
CVE-2016-2781MEDIUM4.6chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIO...
CVE-2016-2779——runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes ...
CVE-2016-2539——Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to...
CVE-2016-1504——dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related t...
CVE-2016-10044HIGH7.8The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which mak...
CVE-2016-9772——OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (...
CVE-2016-9532——Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attacke...
CVE-2016-7800——Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attacker...
CVE-2016-7449——The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service...
CVE-2016-7448——The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumptio...
CVE-2016-7447——Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now