2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0617 | — | — | 0.3% | Sep 30, 2016 | Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via un... |
| CVE-2016-6651 | — | — | 1.7% | Sep 30, 2016 | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and... |
| CVE-2016-6647 | — | — | 1.1% | Sep 30, 2016 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitr... |
| CVE-2016-6637 | — | — | 0.7% | Sep 30, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7... |
| CVE-2016-6636 | — | — | 1.4% | Sep 30, 2016 | The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3... |
| CVE-2016-4386 | — | — | 0.5% | Sep 29, 2016 | HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors. |
| CVE-2016-4385 | — | — | 4.4% | Sep 29, 2016 | The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 all... |
| CVE-2016-7090 | — | — | 1.9% | Sep 29, 2016 | The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure f... |
| CVE-2016-5176 | — | — | 0.8% | Sep 29, 2016 | Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecifi... |
| CVE-2016-5062 | — | — | 3.9% | Sep 29, 2016 | The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, whi... |
| CVE-2016-5061 | — | — | 1.2% | Sep 29, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to... |
| CVE-2016-7568 | — | — | 5.1% | Sep 28, 2016 | Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as us... |
| CVE-2016-7191 | — | — | 29.4% | Sep 28, 2016 | The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for ... |
| CVE-2016-2776 | — | — | 89.5% | Sep 28, 2016 | buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly ... |
| CVE-2016-7498 | — | — | 2.3% | Sep 27, 2016 | OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated... |
| CVE-2016-7444 | — | — | 2.4% | Sep 27, 2016 | The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verif... |
| CVE-2016-7045 | — | — | 4.7% | Sep 27, 2016 | The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a den... |
| CVE-2016-7044 | — | — | 4.7% | Sep 27, 2016 | The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabl... |
| CVE-2016-6330 | — | — | 10.6% | Sep 27, 2016 | The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent c... |
| CVE-2016-6146 | — | — | 2.0% | Sep 27, 2016 | The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecifi... |
| CVE-2016-6137 | — | — | 4.7% | Sep 27, 2016 | An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknow... |
| CVE-2016-4058 | — | — | 0.6% | Sep 27, 2016 | Cross-site scripting (XSS) vulnerability in Huawei Policy Center before V100R003C10SPC020 allows remote authenticated us... |
| CVE-2016-7554 | — | — | — | Sep 26, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-6309 | — | — | 69.7% | Sep 26, 2016 | statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote atta... |
| CVE-2016-6308 | — | — | 14.1% | Sep 26, 2016 | statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an e... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now