2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1479 | — | — | 3.0% | Aug 22, 2016 | Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption... |
| CVE-2016-1476 | — | — | 0.8% | Aug 22, 2016 | Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated u... |
| CVE-2016-6493 | — | — | 2.2% | Aug 19, 2016 | Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken a... |
| CVE-2016-6320 | — | — | 0.9% | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allo... |
| CVE-2016-6319 | — | — | 2.0% | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execu... |
| CVE-2016-6254 | — | — | 5.6% | Aug 19, 2016 | Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allow... |
| CVE-2016-5736 | — | — | 2.3% | Aug 19, 2016 | The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2... |
| CVE-2016-5390 | — | — | 1.3% | Aug 19, 2016 | Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containin... |
| CVE-2016-4995 | — | — | 1.1% | Aug 19, 2016 | Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, whic... |
| CVE-2016-4475 | — | — | 2.7% | Aug 19, 2016 | The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote a... |
| CVE-2016-4451 | — | — | 0.9% | Aug 19, 2016 | The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authentic... |
| CVE-2016-3195 | — | — | 1.0% | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in the Web-UI in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6... |
| CVE-2016-3194 | — | — | 1.0% | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in the address added page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x ... |
| CVE-2016-3193 | — | — | 0.8% | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.... |
| CVE-2016-3089 | — | — | 4.9% | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to... |
| CVE-2016-0760 | — | — | 3.3% | Aug 19, 2016 | Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute ... |
| CVE-2016-4654 | — | — | 1.4% | Aug 18, 2016 | IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or caus... |
| CVE-2016-1458 | — | — | 2.4% | Aug 18, 2016 | The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x bef... |
| CVE-2016-1457 | — | — | 3.7% | Aug 18, 2016 | The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Ada... |
| CVE-2016-1365 | — | — | 2.7% | Aug 18, 2016 | The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allow... |
| CVE-2016-5847 | — | — | 1.0% | Aug 13, 2016 | SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l... |
| CVE-2016-6214 | — | — | 3.2% | Aug 12, 2016 | gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-o... |
| CVE-2016-6161 | — | — | 2.8% | Aug 12, 2016 | The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of ... |
| CVE-2016-6132 | — | — | 3.3% | Aug 12, 2016 | The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to caus... |
| CVE-2016-6597 | — | — | 4.5% | Aug 10, 2016 | Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to acce... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now