2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1894NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vecto...
CVE-2016-1502NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and dele...
CVE-2016-6104IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the imp...
CVE-2016-6097IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another ...
CVE-2016-6096IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows us...
CVE-2016-6094IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information abou...
CVE-2016-6092IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by...
CVE-2016-3020IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restriction...
CVE-2016-7400Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm...
CVE-2016-7164The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segm...
CVE-2016-6199ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized objec...
CVE-2016-6175Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via...
CVE-2016-6131The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and ...
CVE-2016-2781MEDIUM4.6chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIO...
CVE-2016-2779runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes ...
CVE-2016-2539Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to...
CVE-2016-1504dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related t...
CVE-2016-10044HIGH7.8The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which mak...
CVE-2016-9772OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (...
CVE-2016-9532Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attacke...
CVE-2016-7800Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attacker...
CVE-2016-7449The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service...
CVE-2016-7448The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumptio...
CVE-2016-7447Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to ...
CVE-2016-7446Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified i...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now