2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4704 | — | — | 0.3% | Sep 18, 2016 | otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and ... |
| CVE-2016-4620 | — | — | 0.8% | Sep 18, 2016 | The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS dr... |
| CVE-2016-1433 | — | — | 1.6% | Sep 18, 2016 | Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process relo... |
| CVE-2016-6643 | — | — | 0.8% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web sc... |
| CVE-2016-6642 | — | — | 0.4% | Sep 18, 2016 | Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authe... |
| CVE-2016-6641 | — | — | 0.7% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitr... |
| CVE-2016-0930 | — | — | 1.0% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a def... |
| CVE-2016-0929 | — | — | 1.1% | Sep 18, 2016 | The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of fa... |
| CVE-2016-0928 | — | — | 1.4% | Sep 18, 2016 | Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7... |
| CVE-2016-0927 | — | — | 1.0% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attacker... |
| CVE-2016-0926 | — | — | 1.1% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 an... |
| CVE-2016-0924 | — | — | — | Sep 18, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2761. Reason: This candidate is subsumed by CV... |
| CVE-2016-0922 | — | — | 1.5% | Sep 18, 2016 | EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for re... |
| CVE-2016-0897 | — | — | 1.5% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not p... |
| CVE-2016-0896 | — | — | 1.0% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open ... |
| CVE-2016-0883 | — | — | 0.9% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across ... |
| CVE-2016-7419 | — | — | 1.4% | Sep 17, 2016 | Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Next... |
| CVE-2016-7418 | — | — | 11.4% | Sep 17, 2016 | The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers... |
| CVE-2016-7417 | — | — | 6.8% | Sep 17, 2016 | ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating... |
| CVE-2016-7416 | — | — | 6.7% | Sep 17, 2016 | ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale l... |
| CVE-2016-7415 | — | — | 5.8% | Sep 17, 2016 | Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) throug... |
| CVE-2016-7414 | — | — | 6.8% | Sep 17, 2016 | The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_... |
| CVE-2016-7413 | — | — | 6.7% | Sep 17, 2016 | Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7... |
| CVE-2016-7412 | — | — | 8.8% | Sep 17, 2016 | ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the U... |
| CVE-2016-7411 | — | — | 5.6% | Sep 17, 2016 | ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote at... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now