2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9800 | — | — | 2.8% | Dec 3, 2016 | In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The... |
| CVE-2016-9799 | — | — | 2.1% | Dec 3, 2016 | In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be ... |
| CVE-2016-9798 | — | — | 3.8% | Dec 3, 2016 | In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue ... |
| CVE-2016-9797 | — | — | 3.7% | Dec 3, 2016 | In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issu... |
| CVE-2016-9796 | — | — | 13.4% | Dec 3, 2016 | Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP pro... |
| CVE-2016-9638 | — | — | 0.5% | Dec 2, 2016 | In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it... |
| CVE-2016-9479 | — | — | 1.8% | Dec 2, 2016 | The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords ... |
| CVE-2016-9752 | — | — | 1.1% | Dec 1, 2016 | In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1)... |
| CVE-2016-9751 | — | — | 1.1% | Dec 1, 2016 | Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inje... |
| CVE-2016-3055 | — | — | 1.4% | Dec 1, 2016 | IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a d... |
| CVE-2016-3047 | — | — | 0.8% | Dec 1, 2016 | Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to r... |
| CVE-2016-3044 | — | — | 0.4% | Dec 1, 2016 | The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to caus... |
| CVE-2016-3033 | — | — | 1.4% | Dec 1, 2016 | IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of se... |
| CVE-2016-3012 | — | — | 1.7% | Dec 1, 2016 | IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in th... |
| CVE-2016-2994 | — | — | 0.6% | Dec 1, 2016 | Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users ... |
| CVE-2016-2991 | — | — | 0.6% | Dec 1, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 bef... |
| CVE-2016-2955 | — | — | 0.6% | Dec 1, 2016 | Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticate... |
| CVE-2016-2946 | — | — | 0.4% | Dec 1, 2016 | Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2... |
| CVE-2016-2917 | — | — | 1.2% | Nov 30, 2016 | The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to... |
| CVE-2016-2887 | — | — | 0.9% | Nov 30, 2016 | IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sen... |
| CVE-2016-2884 | — | — | 0.5% | Nov 30, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an un... |
| CVE-2016-2881 | — | — | 0.9% | Nov 30, 2016 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote... |
| CVE-2016-2878 | — | — | 0.5% | Nov 30, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2... |
| CVE-2016-2877 | — | — | 0.3% | Nov 30, 2016 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the... |
| CVE-2016-2876 | — | — | 1.6% | Nov 30, 2016 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege le... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now