2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2929 | — | — | 1.3% | Nov 25, 2016 | IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote att... |
| CVE-2016-2928 | — | — | 1.0% | Nov 25, 2016 | IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading erro... |
| CVE-2016-2927 | — | — | 0.8% | Nov 25, 2016 | IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which make... |
| CVE-2016-2926 | — | — | 1.2% | Nov 25, 2016 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0... |
| CVE-2016-0319 | — | — | 1.6% | Nov 25, 2016 | The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows r... |
| CVE-2016-0318 | — | — | 0.6% | Nov 25, 2016 | Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session... |
| CVE-2016-0317 | — | — | 0.9% | Nov 25, 2016 | Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to... |
| CVE-2016-0316 | — | — | 0.6% | Nov 25, 2016 | Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 bef... |
| CVE-2016-9621 | — | — | — | Nov 25, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9429. Reason: This candidate is a reservation ... |
| CVE-2016-9452 | — | — | 1.7% | Nov 25, 2016 | The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafte... |
| CVE-2016-9451 | — | — | 1.5% | Nov 25, 2016 | Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect atta... |
| CVE-2016-9450 | — | — | 1.0% | Nov 25, 2016 | The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by le... |
| CVE-2016-9449 | — | — | 2.0% | Nov 25, 2016 | The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sens... |
| CVE-2016-3919 | — | — | — | Nov 25, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5195. Reason: This candidate is a reservation ... |
| CVE-2016-6754 | — | — | 4.6% | Nov 25, 2016 | A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-... |
| CVE-2016-6753 | — | — | 0.5% | Nov 25, 2016 | An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networkin... |
| CVE-2016-6752 | — | — | 0.4% | Nov 25, 2016 | An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Poi... |
| CVE-2016-6751 | — | — | 0.4% | Nov 25, 2016 | An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Poi... |
| CVE-2016-6750 | — | — | 0.4% | Nov 25, 2016 | An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Poi... |
| CVE-2016-6749 | — | — | 0.4% | Nov 25, 2016 | An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Poi... |
| CVE-2016-6748 | — | — | 0.4% | Nov 25, 2016 | An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Poi... |
| CVE-2016-6747 | — | — | 0.5% | Nov 25, 2016 | A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a speciall... |
| CVE-2016-6746 | — | — | 0.4% | Nov 25, 2016 | An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malic... |
| CVE-2016-6745 | — | — | 0.7% | Nov 25, 2016 | An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a ... |
| CVE-2016-6744 | — | — | 0.7% | Nov 25, 2016 | An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now