2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6521 | — | — | 0.8% | Jan 23, 2017 | Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.... |
| CVE-2016-6517 | — | — | 2.4% | Jan 23, 2017 | Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (enco... |
| CVE-2016-6484 | — | — | 1.8% | Jan 23, 2017 | CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitr... |
| CVE-2016-6223 | — | — | 3.3% | Jan 23, 2017 | The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to ca... |
| CVE-2016-6164 | — | — | 1.8% | Jan 23, 2017 | Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1... |
| CVE-2016-6160 | — | — | 2.2% | Jan 23, 2017 | tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a lar... |
| CVE-2016-5876 | — | — | 1.2% | Jan 23, 2017 | ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download ... |
| CVE-2016-5873 | — | — | 4.7% | Jan 23, 2017 | Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbi... |
| CVE-2016-5742 | — | — | 1.6% | Jan 23, 2017 | SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before ... |
| CVE-2016-5720 | — | — | 1.9% | Jan 23, 2017 | Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduc... |
| CVE-2016-5697 | — | — | 1.2% | Jan 23, 2017 | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. |
| CVE-2016-5237 | — | — | 0.8% | Jan 23, 2017 | Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m... |
| CVE-2016-5119 | — | — | 2.3% | Jan 23, 2017 | The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by... |
| CVE-2016-5091 | — | — | 2.6% | Jan 23, 2017 | Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive informatio... |
| CVE-2016-4793 | — | — | 5.1% | Jan 23, 2017 | The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head... |
| CVE-2016-4484 | — | — | 0.7% | Jan 23, 2017 | The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain ... |
| CVE-2016-4340 | — | — | 10.1% | Jan 23, 2017 | The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8... |
| CVE-2016-4338 | — | — | 21.1% | Jan 23, 2017 | The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef... |
| CVE-2016-4056 | — | — | 1.1% | Jan 23, 2017 | Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers t... |
| CVE-2016-4055 | MEDIUM | 6.5 | 9.9% | Jan 23, 2017 | The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of servi... |
| CVE-2016-4010 | — | — | 92.9% | Jan 23, 2017 | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary ... |
| CVE-2016-3177 | — | — | 1.6% | Jan 23, 2017 | Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack... |
| CVE-2016-3147 | CRITICAL | 9.8 | 5.7% | Jan 23, 2017 | Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attac... |
| CVE-2016-2783 | — | — | 4.4% | Jan 23, 2017 | Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.... |
| CVE-2016-2242 | — | — | 6.6% | Jan 23, 2017 | Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now