2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1000107MEDIUM6.1inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications fr...
CVE-2016-1000108MEDIUM6.1yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect...
CVE-2016-1000104HIGH8.8A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
CVE-2016-1000021Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10538. Reason: This candidate is a duplicate of ...
CVE-2016-1000110MEDIUM6.1The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script...
CVE-2016-4980LOW2.5A password generation weakness exists in xquest through 2016-06-13.
CVE-2016-9271MEDIUM5.4Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
CVE-2016-6353MEDIUM6.5Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass S...
CVE-2016-5724HIGH7.5Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
CVE-2016-4572HIGH8.8In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
CVE-2016-3192MEDIUM6.5Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
CVE-2016-3131MEDIUM6.5Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
CVE-2016-9652CRITICAL9.8Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.
CVE-2016-5194CRITICAL9.8Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
CVE-2016-1000236MEDIUM4.4Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVE-2016-1000006CRITICAL9.8hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
CVE-2016-5285HIGH7.5A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11...
CVE-2016-1000037MEDIUM6.1Pagure: XSS possible in file attachment endpoint
CVE-2016-4401CRITICAL9.8Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
CVE-2016-4983LOW3.3A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
CVE-2016-1000002LOW2.4gdm3 3.14.2 and possibly later has an information leak before screen lock
CVE-2016-9047Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-9046Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-8381Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-4289MEDIUM5.5A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now