2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-0913The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC ...
CVE-2016-4990Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-8280Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read ar...
CVE-2016-8278Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attac...
CVE-2016-8277Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authe...
CVE-2016-8276Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG...
CVE-2016-7141curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote a...
CVE-2016-7046Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allo...
CVE-2016-6905The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to c...
CVE-2016-7572The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, wh...
CVE-2016-7571Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web scr...
CVE-2016-7570Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated...
CVE-2016-7405The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to ...
CVE-2016-7401The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allo...
CVE-2016-7031The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list ...
CVE-2016-6494The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain...
CVE-2016-6352The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out...
CVE-2016-5432The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain...
CVE-2016-5398Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remot...
CVE-2016-5019CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2...
CVE-2016-1372ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a...
CVE-2016-1371ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a...
CVE-2016-1244The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a direct...
CVE-2016-1243Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a...
CVE-2016-7445convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and ap...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now