2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6670 | — | — | 0.8% | Sep 7, 2016 | Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficie... |
| CVE-2016-6318 | HIGH | 7.8 | 0.7% | Sep 7, 2016 | Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a ... |
| CVE-2016-6317 | — | — | 3.9% | Sep 7, 2016 | Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between... |
| CVE-2016-6316 | — | — | 3.4% | Sep 7, 2016 | Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.... |
| CVE-2016-6184 | — | — | 0.2% | Sep 7, 2016 | The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH... |
| CVE-2016-6183 | — | — | 0.2% | Sep 7, 2016 | The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH... |
| CVE-2016-6182 | — | — | 0.6% | Sep 7, 2016 | The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH... |
| CVE-2016-6181 | — | — | 0.2% | Sep 7, 2016 | The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH... |
| CVE-2016-6180 | — | — | 0.2% | Sep 7, 2016 | The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH... |
| CVE-2016-5422 | — | — | 2.1% | Sep 7, 2016 | The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users... |
| CVE-2016-5022 | — | — | 3.5% | Sep 7, 2016 | F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 ... |
| CVE-2016-1242 | — | — | 1.8% | Sep 7, 2016 | file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 al... |
| CVE-2016-1241 | — | — | 1.6% | Sep 7, 2016 | Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remot... |
| CVE-2016-7034 | — | — | 1.1% | Sep 7, 2016 | The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session... |
| CVE-2016-7033 | — | — | 1.5% | Sep 7, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 a... |
| CVE-2016-6855 | — | — | 18.9% | Sep 7, 2016 | Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib befor... |
| CVE-2016-6351 | MEDIUM | 6.7 | 0.5% | Sep 7, 2016 | The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation... |
| CVE-2016-6346 | — | — | 4.9% | Sep 7, 2016 | RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors. |
| CVE-2016-6345 | — | — | 1.5% | Sep 7, 2016 | RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random val... |
| CVE-2016-6344 | — | — | 2.2% | Sep 7, 2016 | Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes... |
| CVE-2016-7153 | — | — | 14.0% | Sep 6, 2016 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content lengt... |
| CVE-2016-7152 | — | — | 14.0% | Sep 6, 2016 | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length... |
| CVE-2016-7114 | — | — | 2.1% | Sep 6, 2016 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;... |
| CVE-2016-7113 | — | — | 3.0% | Sep 6, 2016 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;... |
| CVE-2016-7112 | — | — | 2.9% | Sep 6, 2016 | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now