2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6582——The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary toke...
CVE-2016-6521——Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0....
CVE-2016-6517——Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (enco...
CVE-2016-6484——CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitr...
CVE-2016-6223——The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to ca...
CVE-2016-6164——Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1...
CVE-2016-6160——tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a lar...
CVE-2016-5876——ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download ...
CVE-2016-5873——Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbi...
CVE-2016-5742——SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before ...
CVE-2016-5720——Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduc...
CVE-2016-5697——Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
CVE-2016-5237——Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m...
CVE-2016-5119——The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by...
CVE-2016-5091——Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive informatio...
CVE-2016-4793——The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head...
CVE-2016-4484——The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain ...
CVE-2016-4340——The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8...
CVE-2016-4338——The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef...
CVE-2016-4056——Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers t...
CVE-2016-4055MEDIUM6.5The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of servi...
CVE-2016-4010——Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary ...
CVE-2016-3177——Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack...
CVE-2016-3147CRITICAL9.8Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attac...
CVE-2016-2783——Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0....

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now