2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1000107 | MEDIUM | 6.1 | 1.4% | Dec 10, 2019 | inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications fr... |
| CVE-2016-1000108 | MEDIUM | 6.1 | 1.1% | Dec 10, 2019 | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect... |
| CVE-2016-1000104 | HIGH | 8.8 | 2.2% | Dec 3, 2019 | A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. |
| CVE-2016-1000021 | — | — | — | Dec 3, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10538. Reason: This candidate is a duplicate of ... |
| CVE-2016-1000110 | MEDIUM | 6.1 | 4.6% | Nov 27, 2019 | The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script... |
| CVE-2016-4980 | LOW | 2.5 | 0.3% | Nov 27, 2019 | A password generation weakness exists in xquest through 2016-06-13. |
| CVE-2016-9271 | MEDIUM | 5.4 | 0.5% | Nov 26, 2019 | Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature. |
| CVE-2016-6353 | MEDIUM | 6.5 | 0.8% | Nov 26, 2019 | Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass S... |
| CVE-2016-5724 | HIGH | 7.5 | 1.2% | Nov 26, 2019 | Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles. |
| CVE-2016-4572 | HIGH | 8.8 | 0.9% | Nov 26, 2019 | In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. |
| CVE-2016-3192 | MEDIUM | 6.5 | 0.6% | Nov 26, 2019 | Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files. |
| CVE-2016-3131 | MEDIUM | 6.5 | 0.7% | Nov 26, 2019 | Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. |
| CVE-2016-9652 | CRITICAL | 9.8 | 2.1% | Nov 20, 2019 | Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75. |
| CVE-2016-5194 | CRITICAL | 9.8 | 0.7% | Nov 20, 2019 | Unspecified vulnerabilities in Google Chrome before 54.0.2840.59. |
| CVE-2016-1000236 | MEDIUM | 4.4 | 0.9% | Nov 19, 2019 | Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used. |
| CVE-2016-1000006 | CRITICAL | 9.8 | 1.6% | Nov 19, 2019 | hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions. |
| CVE-2016-5285 | HIGH | 7.5 | 2.3% | Nov 15, 2019 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11... |
| CVE-2016-1000037 | MEDIUM | 6.1 | 1.1% | Nov 6, 2019 | Pagure: XSS possible in file attachment endpoint |
| CVE-2016-4401 | CRITICAL | 9.8 | 1.4% | Nov 6, 2019 | Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials. |
| CVE-2016-4983 | LOW | 3.3 | 0.4% | Nov 5, 2019 | A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. |
| CVE-2016-1000002 | LOW | 2.4 | 0.5% | Nov 5, 2019 | gdm3 3.14.2 and possibly later has an information leak before screen lock |
| CVE-2016-9047 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-9046 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-8381 | — | — | — | Oct 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-4289 | MEDIUM | 5.5 | 0.6% | Oct 29, 2019 | A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now