2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4386HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors.
CVE-2016-4385The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 all...
CVE-2016-7090The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure f...
CVE-2016-5176Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecifi...
CVE-2016-5062The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, whi...
CVE-2016-5061Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to...
CVE-2016-7568Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as us...
CVE-2016-7191The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for ...
CVE-2016-2776buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly ...
CVE-2016-7498OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated...
CVE-2016-7444The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verif...
CVE-2016-7045The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a den...
CVE-2016-7044The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabl...
CVE-2016-6330The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent c...
CVE-2016-6146The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecifi...
CVE-2016-6137An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknow...
CVE-2016-4978HIGH7.2The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemi...
CVE-2016-4058Cross-site scripting (XSS) vulnerability in Huawei Policy Center before V100R003C10SPC020 allows remote authenticated us...
CVE-2016-7554Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-7052HIGH7.5crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference ...
CVE-2016-6309statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote atta...
CVE-2016-6308statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an e...
CVE-2016-6307The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length...
CVE-2016-6306MEDIUM5.9The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial o...
CVE-2016-6305The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now