2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6346 | — | — | 4.9% | Sep 7, 2016 | RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors. |
| CVE-2016-6345 | — | — | 1.5% | Sep 7, 2016 | RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random val... |
| CVE-2016-6344 | — | — | 2.2% | Sep 7, 2016 | Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes... |
| CVE-2016-7153 | — | — | 14.0% | Sep 6, 2016 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content lengt... |
| CVE-2016-7152 | — | — | 14.0% | Sep 6, 2016 | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length... |
| CVE-2016-7114 | — | — | 2.1% | Sep 6, 2016 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;... |
| CVE-2016-7113 | — | — | 3.0% | Sep 6, 2016 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;... |
| CVE-2016-7112 | — | — | 2.9% | Sep 6, 2016 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;... |
| CVE-2016-6377 | — | — | 1.3% | Sep 3, 2016 | Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to... |
| CVE-2016-1464 | — | — | 10.0% | Sep 3, 2016 | Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code ... |
| CVE-2016-1415 | — | — | 5.6% | Sep 3, 2016 | Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi... |
| CVE-2016-7123 | — | — | 1.5% | Sep 2, 2016 | Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote at... |
| CVE-2016-6893 | — | — | 1.6% | Sep 2, 2016 | Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remot... |
| CVE-2016-5879 | — | — | 0.4% | Sep 2, 2016 | MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (... |
| CVE-2016-5699 | — | — | 9.9% | Sep 2, 2016 | CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) befo... |
| CVE-2016-5636 | — | — | 25.7% | Sep 2, 2016 | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.... |
| CVE-2016-0772 | — | — | 14.5% | Sep 2, 2016 | The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an e... |
| CVE-2016-6483 | — | — | 11.9% | Sep 2, 2016 | The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Le... |
| CVE-2016-4853 | — | — | 1.5% | Sep 2, 2016 | AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Ha... |
| CVE-2016-4851 | — | — | 1.2% | Sep 2, 2016 | Cross-site scripting (XSS) vulnerability in Let's PHP! simple chat before 2016-08-15 allows remote attackers to inject a... |
| CVE-2016-4848 | — | — | 1.6% | Sep 2, 2016 | Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1 RC2 allows remote attackers to inject arbitrary web ... |
| CVE-2016-6376 | — | — | 0.9% | Sep 2, 2016 | The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8... |
| CVE-2016-1473 | — | — | 4.0% | Sep 2, 2016 | Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attac... |
| CVE-2016-1472 | — | — | 2.9% | Sep 2, 2016 | The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attack... |
| CVE-2016-1471 | — | — | 1.5% | Sep 2, 2016 | Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now