2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1894 | — | — | 2.8% | Feb 7, 2017 | NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vecto... |
| CVE-2016-1502 | — | — | 1.6% | Feb 7, 2017 | NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and dele... |
| CVE-2016-6104 | — | — | 2.7% | Feb 7, 2017 | IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the imp... |
| CVE-2016-6097 | — | — | 0.3% | Feb 7, 2017 | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another ... |
| CVE-2016-6096 | — | — | 0.9% | Feb 7, 2017 | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows us... |
| CVE-2016-6094 | — | — | 0.9% | Feb 7, 2017 | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information abou... |
| CVE-2016-6092 | — | — | 0.3% | Feb 7, 2017 | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by... |
| CVE-2016-3020 | — | — | 1.2% | Feb 7, 2017 | IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restriction... |
| CVE-2016-7400 | — | — | 4.7% | Feb 7, 2017 | Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm... |
| CVE-2016-7164 | — | — | 2.6% | Feb 7, 2017 | The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segm... |
| CVE-2016-6199 | — | — | 4.7% | Feb 7, 2017 | ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized objec... |
| CVE-2016-6175 | — | — | 19.7% | Feb 7, 2017 | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via... |
| CVE-2016-6131 | — | — | 4.6% | Feb 7, 2017 | The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and ... |
| CVE-2016-2781 | MEDIUM | 4.6 | 0.4% | Feb 7, 2017 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIO... |
| CVE-2016-2779 | — | — | 0.4% | Feb 7, 2017 | runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes ... |
| CVE-2016-2539 | — | — | 4.3% | Feb 7, 2017 | Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to... |
| CVE-2016-1504 | — | — | 2.9% | Feb 7, 2017 | dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related t... |
| CVE-2016-10044 | HIGH | 7.8 | 0.3% | Feb 7, 2017 | The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which mak... |
| CVE-2016-9772 | — | — | 1.7% | Feb 6, 2017 | OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (... |
| CVE-2016-9532 | — | — | 2.0% | Feb 6, 2017 | Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attacke... |
| CVE-2016-7800 | — | — | 3.8% | Feb 6, 2017 | Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attacker... |
| CVE-2016-7449 | — | — | 3.5% | Feb 6, 2017 | The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service... |
| CVE-2016-7448 | — | — | 3.8% | Feb 6, 2017 | The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumptio... |
| CVE-2016-7447 | — | — | 4.0% | Feb 6, 2017 | Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to ... |
| CVE-2016-7446 | — | — | 4.0% | Feb 6, 2017 | Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified i... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now