2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4747 | — | — | 0.7% | Sep 18, 2016 | Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover m... |
| CVE-2016-4746 | — | — | 1.8% | Sep 18, 2016 | The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows ... |
| CVE-2016-4741 | — | — | 1.4% | Sep 18, 2016 | The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors rel... |
| CVE-2016-4740 | — | — | 0.3% | Sep 18, 2016 | Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displ... |
| CVE-2016-4719 | — | — | 1.0% | Sep 18, 2016 | The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData inf... |
| CVE-2016-4705 | — | — | 0.3% | Sep 18, 2016 | otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and ... |
| CVE-2016-4704 | — | — | 0.3% | Sep 18, 2016 | otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and ... |
| CVE-2016-4620 | — | — | 0.8% | Sep 18, 2016 | The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS dr... |
| CVE-2016-1433 | — | — | 1.6% | Sep 18, 2016 | Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process relo... |
| CVE-2016-6643 | — | — | 0.8% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web sc... |
| CVE-2016-6642 | — | — | 0.4% | Sep 18, 2016 | Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authe... |
| CVE-2016-6641 | — | — | 0.7% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitr... |
| CVE-2016-6639 | HIGH | 7.5 | 1.7% | Sep 18, 2016 | Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivota... |
| CVE-2016-0930 | — | — | 1.0% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a def... |
| CVE-2016-0929 | — | — | 1.1% | Sep 18, 2016 | The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of fa... |
| CVE-2016-0928 | — | — | 1.4% | Sep 18, 2016 | Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7... |
| CVE-2016-0927 | — | — | 1.0% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attacker... |
| CVE-2016-0926 | — | — | 1.1% | Sep 18, 2016 | Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 an... |
| CVE-2016-0924 | — | — | — | Sep 18, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2761. Reason: This candidate is subsumed by CV... |
| CVE-2016-0923 | HIGH | 7.5 | 1.6% | Sep 18, 2016 | The client in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.9 and 4.1.x before 4.1.5 places the weakest algor... |
| CVE-2016-0922 | — | — | 1.5% | Sep 18, 2016 | EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for re... |
| CVE-2016-0897 | — | — | 1.5% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not p... |
| CVE-2016-0896 | — | — | 1.0% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open ... |
| CVE-2016-0883 | — | — | 0.9% | Sep 18, 2016 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across ... |
| CVE-2016-7419 | — | — | 1.4% | Sep 17, 2016 | Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Next... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now