2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1189 | — | — | 1.2% | Jun 25, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, cre... |
| CVE-2016-1188 | — | — | 1.1% | Jun 25, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified... |
| CVE-2016-4528 | — | — | 0.7% | Jun 25, 2016 | Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted... |
| CVE-2016-4525 | — | — | 0.4% | Jun 25, 2016 | Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensi... |
| CVE-2016-4519 | — | — | 4.5% | Jun 25, 2016 | Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary ... |
| CVE-2016-5723 | — | — | 0.2% | Jun 24, 2016 | Huawei FusionInsight HD before V100R002C60SPC200 allows local users to gain root privileges via unspecified vectors. |
| CVE-2016-5722 | — | — | 0.7% | Jun 24, 2016 | Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaint... |
| CVE-2016-5709 | — | — | 1.4% | Jun 24, 2016 | SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows... |
| CVE-2016-5435 | — | — | 1.0% | Jun 24, 2016 | Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and A... |
| CVE-2016-5021 | — | — | 1.2% | Jun 24, 2016 | The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4... |
| CVE-2016-4802 | — | — | 0.6% | Jun 24, 2016 | Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enab... |
| CVE-2016-1439 | — | — | 0.8% | Jun 23, 2016 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through ... |
| CVE-2016-1438 | — | — | 1.2% | Jun 23, 2016 | Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filter... |
| CVE-2016-1437 | — | — | 1.4% | Jun 23, 2016 | SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote auth... |
| CVE-2016-1436 | — | — | 1.8% | Jun 23, 2016 | The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network... |
| CVE-2016-1435 | — | — | 0.3% | Jun 23, 2016 | Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users... |
| CVE-2016-1434 | — | — | 0.8% | Jun 23, 2016 | The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated user... |
| CVE-2016-1428 | — | — | 1.2% | Jun 23, 2016 | Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of... |
| CVE-2016-0914 | — | — | 1.3% | Jun 23, 2016 | EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, D... |
| CVE-2016-2364 | — | — | 2.3% | Jun 20, 2016 | The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardco... |
| CVE-2016-2363 | — | — | 0.6% | Jun 20, 2016 | Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun ... |
| CVE-2016-2362 | — | — | 2.5% | Jun 20, 2016 | Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, whi... |
| CVE-2016-2177 | — | — | 44.5% | Jun 20, 2016 | OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote att... |
| CVE-2016-4811 | — | — | 0.8% | Jun 19, 2016 | The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier ... |
| CVE-2016-4518 | — | — | 1.2% | Jun 19, 2016 | OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) v... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now