2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6521Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0....
CVE-2016-6517Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (enco...
CVE-2016-6484CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitr...
CVE-2016-6223The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to ca...
CVE-2016-6164Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1...
CVE-2016-6160tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a lar...
CVE-2016-5876ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download ...
CVE-2016-5873Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbi...
CVE-2016-5742SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before ...
CVE-2016-5720Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduc...
CVE-2016-5697Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
CVE-2016-5237Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m...
CVE-2016-5119The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by...
CVE-2016-5091Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive informatio...
CVE-2016-4793The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head...
CVE-2016-4484The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain ...
CVE-2016-4340The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8...
CVE-2016-4338The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef...
CVE-2016-4056Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers t...
CVE-2016-4055MEDIUM6.5The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of servi...
CVE-2016-4010Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary ...
CVE-2016-3177Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack...
CVE-2016-3147CRITICAL9.8Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attac...
CVE-2016-2783Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0....
CVE-2016-2242Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now