2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3819 | — | — | 1.7% | Aug 5, 2016 | Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4... |
| CVE-2016-2504 | — | — | 0.2% | Aug 5, 2016 | The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gai... |
| CVE-2016-2497 | — | — | 0.6% | Aug 5, 2016 | services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android 4.x before 4.4.4, 5... |
| CVE-2016-6186 | — | — | 5.5% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/j... |
| CVE-2016-5392 | — | — | 2.5% | Aug 5, 2016 | The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote a... |
| CVE-2016-1278 | — | — | 0.4% | Aug 5, 2016 | Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logi... |
| CVE-2016-1276 | — | — | 2.1% | Aug 5, 2016 | Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-... |
| CVE-2016-0782 | — | — | 6.1% | Aug 5, 2016 | The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allo... |
| CVE-2016-6150 | — | — | 2.9% | Aug 5, 2016 | The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote at... |
| CVE-2016-6149 | — | — | 0.5% | Aug 5, 2016 | SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statemen... |
| CVE-2016-6148 | — | — | 4.3% | Aug 5, 2016 | SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbi... |
| CVE-2016-6147 | — | — | 4.5% | Aug 5, 2016 | An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDa... |
| CVE-2016-6145 | — | — | 1.5% | Aug 5, 2016 | The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depe... |
| CVE-2016-6144 | — | — | 3.8% | Aug 5, 2016 | The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when t... |
| CVE-2016-6140 | — | — | 5.5% | Aug 5, 2016 | SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SA... |
| CVE-2016-6139 | — | — | 4.2% | Aug 5, 2016 | SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note... |
| CVE-2016-6138 | — | — | 5.8% | Aug 5, 2016 | Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspe... |
| CVE-2016-5000 | — | — | 4.2% | Aug 5, 2016 | The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML doc... |
| CVE-2016-3640 | — | — | 0.4% | Aug 5, 2016 | The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obta... |
| CVE-2016-3196 | — | — | 1.0% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiMan... |
| CVE-2016-3097 | — | — | 1.1% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject ar... |
| CVE-2016-3080 | — | — | 1.1% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject ar... |
| CVE-2016-1513 | — | — | 4.4% | Aug 5, 2016 | The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bou... |
| CVE-2016-5268 | — | — | 1.2% | Aug 5, 2016 | Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs t... |
| CVE-2016-5267 | — | — | 0.9% | Aug 5, 2016 | Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now