2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6825——Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software ...
CVE-2016-6670——Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficie...
CVE-2016-6318HIGH7.8Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a ...
CVE-2016-6317——Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between...
CVE-2016-6316——Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5....
CVE-2016-6184——The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH...
CVE-2016-6183——The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH...
CVE-2016-6182——The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH...
CVE-2016-6181——The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH...
CVE-2016-6180——The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CH...
CVE-2016-5422——The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users...
CVE-2016-5022——F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 ...
CVE-2016-1242——file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 al...
CVE-2016-1241——Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remot...
CVE-2016-7034——The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session...
CVE-2016-7033——Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 a...
CVE-2016-6855——Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib befor...
CVE-2016-6351MEDIUM6.7The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation...
CVE-2016-6346——RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2016-6345——RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random val...
CVE-2016-6344——Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes...
CVE-2016-7153——The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content lengt...
CVE-2016-7152——The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length...
CVE-2016-7114——A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;...
CVE-2016-7113——A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now