2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6820——MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext whi...
CVE-2016-4808——Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack...
CVE-2016-4807——Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS...
CVE-2016-4806——Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u...
CVE-2016-7480CRITICAL9.8The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a ke...
CVE-2016-7478——Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a deni...
CVE-2016-6091——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1897, CVE-2015-0119. Reason: This candidate is...
CVE-2016-9247——Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics p...
CVE-2016-6837——Cross-site scripting (XSS) vulnerability in MantisBT Filter API in MantisBT versions before 1.2.19, and versions 2.0.0-b...
CVE-2016-6831——The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, result...
CVE-2016-6830——The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments...
CVE-2016-6581——A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted ...
CVE-2016-6580——A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted ...
CVE-2016-6287——The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed v...
CVE-2016-6286——The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which w...
CVE-2016-10126——Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3....
CVE-2016-8106——A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows...
CVE-2016-10125——D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle at...
CVE-2016-10124——An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpri...
CVE-2016-9885——An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The ...
CVE-2016-9879——An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Sec...
CVE-2016-9869——An issue was discovered in EMC ScaleIO versions before 2.0.1.1. Incorrect permissions on the SCINI driver may allow a lo...
CVE-2016-9868——An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may cause a denial-of-se...
CVE-2016-9867——An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify th...
CVE-2016-9886——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now