2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1000022——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10539. Reason: This candidate is a duplicate of ...
CVE-2016-1000107MEDIUM6.1inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications fr...
CVE-2016-1000108MEDIUM6.1yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect...
CVE-2016-1000104HIGH8.8A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
CVE-2016-1000021——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10538. Reason: This candidate is a duplicate of ...
CVE-2016-1000110MEDIUM6.1The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script...
CVE-2016-4980LOW2.5A password generation weakness exists in xquest through 2016-06-13.
CVE-2016-9271MEDIUM5.4Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
CVE-2016-6353MEDIUM6.5Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass S...
CVE-2016-5724HIGH7.5Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
CVE-2016-4572HIGH8.8In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
CVE-2016-3192MEDIUM6.5Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
CVE-2016-3131MEDIUM6.5Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
CVE-2016-9652CRITICAL9.8Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.
CVE-2016-5194CRITICAL9.8Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
CVE-2016-1000236MEDIUM4.4Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVE-2016-1000006CRITICAL9.8hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
CVE-2016-5285HIGH7.5A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11...
CVE-2016-1000037MEDIUM6.1Pagure: XSS possible in file attachment endpoint
CVE-2016-4401CRITICAL9.8Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
CVE-2016-4983LOW3.3A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
CVE-2016-1000002LOW2.4gdm3 3.14.2 and possibly later has an information leak before screen lock
CVE-2016-9047——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-9046——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-8381——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now