2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2871——IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which all...
CVE-2016-2869——Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before ...
CVE-2016-8222——A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an at...
CVE-2016-9564——Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request request...
CVE-2016-5987——IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote atta...
CVE-2016-5905——Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 I...
CVE-2016-5890——IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to chang...
CVE-2016-3057——Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_...
CVE-2016-3014——Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and ...
CVE-2016-3009——Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 ...
CVE-2016-3004——Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 ...
CVE-2016-3002——IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sen...
CVE-2016-2963——Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hij...
CVE-2016-2958——IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensiti...
CVE-2016-2957——IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensiti...
CVE-2016-2953——IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers...
CVE-2016-2952——IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote a...
CVE-2016-2951——IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for ...
CVE-2016-2950——SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbit...
CVE-2016-2949——IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages fr...
CVE-2016-2948——IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
CVE-2016-2944——IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remot...
CVE-2016-2943——IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified priv...
CVE-2016-2940——Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitiv...
CVE-2016-2937——IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmiss...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now