2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0917 | — | — | 4.2% | Sep 21, 2016 | The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Envi... |
| CVE-2016-0905 | — | — | 0.4% | Sep 21, 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obta... |
| CVE-2016-0904 | — | — | 1.4% | Sep 21, 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption k... |
| CVE-2016-0903 | — | — | 3.4% | Sep 21, 2016 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authe... |
| CVE-2016-6802 | — | — | 9.7% | Sep 20, 2016 | Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non... |
| CVE-2016-6662 | — | — | 67.7% | Sep 20, 2016 | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2... |
| CVE-2016-6537 | — | — | 1.3% | Sep 19, 2016 | AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require... |
| CVE-2016-6536 | — | — | 2.6% | Sep 19, 2016 | The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass inte... |
| CVE-2016-6535 | — | — | 2.3% | Sep 19, 2016 | AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers t... |
| CVE-2016-5814 | — | — | 4.7% | Sep 19, 2016 | Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition,... |
| CVE-2016-4860 | — | — | 2.6% | Sep 19, 2016 | Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, ... |
| CVE-2016-4526 | — | — | 0.3% | Sep 19, 2016 | ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directo... |
| CVE-2016-1483 | — | — | 1.9% | Sep 19, 2016 | Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly acc... |
| CVE-2016-0870 | — | — | 1.2% | Sep 19, 2016 | The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via... |
| CVE-2016-6405 | — | — | 1.2% | Sep 18, 2016 | Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to ... |
| CVE-2016-6404 | — | — | 1.0% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allo... |
| CVE-2016-6403 | — | — | 1.6% | Sep 18, 2016 | The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remot... |
| CVE-2016-6402 | — | — | 0.4% | Sep 18, 2016 | UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users ... |
| CVE-2016-4749 | — | — | 0.3% | Sep 18, 2016 | Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext A... |
| CVE-2016-4747 | — | — | 0.7% | Sep 18, 2016 | Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover m... |
| CVE-2016-4746 | — | — | 1.8% | Sep 18, 2016 | The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows ... |
| CVE-2016-4741 | — | — | 1.4% | Sep 18, 2016 | The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors rel... |
| CVE-2016-4740 | — | — | 0.3% | Sep 18, 2016 | Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displ... |
| CVE-2016-4719 | — | — | 1.0% | Sep 18, 2016 | The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData inf... |
| CVE-2016-4705 | — | — | 0.3% | Sep 18, 2016 | otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now