2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2874 | — | — | 0.6% | Nov 30, 2016 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated... |
| CVE-2016-2873 | — | — | 1.1% | Nov 30, 2016 | SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated ... |
| CVE-2016-2871 | — | — | 0.3% | Nov 30, 2016 | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which all... |
| CVE-2016-2869 | — | — | 0.6% | Nov 30, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before ... |
| CVE-2016-8222 | — | — | 0.3% | Nov 30, 2016 | A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an at... |
| CVE-2016-9564 | — | — | 1.4% | Nov 30, 2016 | Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request request... |
| CVE-2016-5987 | — | — | 2.5% | Nov 30, 2016 | IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote atta... |
| CVE-2016-5905 | — | — | 0.6% | Nov 30, 2016 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 I... |
| CVE-2016-5890 | — | — | 1.1% | Nov 30, 2016 | IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to chang... |
| CVE-2016-3057 | — | — | 1.1% | Nov 30, 2016 | Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_... |
| CVE-2016-3014 | — | — | 1.3% | Nov 30, 2016 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and ... |
| CVE-2016-3009 | — | — | 0.5% | Nov 30, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 ... |
| CVE-2016-3004 | — | — | 0.5% | Nov 30, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 ... |
| CVE-2016-3002 | — | — | 0.3% | Nov 30, 2016 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sen... |
| CVE-2016-2963 | — | — | 0.6% | Nov 30, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hij... |
| CVE-2016-2958 | — | — | 1.7% | Nov 30, 2016 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensiti... |
| CVE-2016-2957 | — | — | 1.2% | Nov 30, 2016 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensiti... |
| CVE-2016-2953 | — | — | 1.3% | Nov 30, 2016 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers... |
| CVE-2016-2952 | — | — | 1.6% | Nov 30, 2016 | IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote a... |
| CVE-2016-2951 | — | — | 0.7% | Nov 30, 2016 | IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for ... |
| CVE-2016-2950 | — | — | 1.1% | Nov 30, 2016 | SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbit... |
| CVE-2016-2949 | — | — | 0.3% | Nov 30, 2016 | IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages fr... |
| CVE-2016-2948 | — | — | 0.3% | Nov 30, 2016 | IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors. |
| CVE-2016-2944 | — | — | 1.5% | Nov 30, 2016 | IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remot... |
| CVE-2016-2943 | — | — | 0.3% | Nov 30, 2016 | IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified priv... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now