2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1238 | HIGH | 7.8 | 0.8% | Aug 2, 2016 | (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scrip... |
| CVE-2016-5672 | — | — | 1.7% | Aug 1, 2016 | Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 inter... |
| CVE-2016-5138 | — | — | 1.2% | Aug 1, 2016 | Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0... |
| CVE-2016-4837 | CRITICAL | 9.8 | 2.1% | Aug 1, 2016 | SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrar... |
| CVE-2016-4834 | — | — | 2.2% | Aug 1, 2016 | modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allow... |
| CVE-2016-4373 | — | — | 4.4% | Aug 1, 2016 | The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execut... |
| CVE-2016-3120 | — | — | 4.6% | Aug 1, 2016 | The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before ... |
| CVE-2016-2180 | — | — | 28.5% | Aug 1, 2016 | The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) imp... |
| CVE-2016-1611 | — | — | 1.2% | Aug 1, 2016 | Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.... |
| CVE-2016-1610 | — | — | 11.5% | Aug 1, 2016 | Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo... |
| CVE-2016-1609 | — | — | 3.2% | Aug 1, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security ... |
| CVE-2016-1608 | — | — | 11.3% | Aug 1, 2016 | vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated u... |
| CVE-2016-1607 | — | — | 3.4% | Aug 1, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Sec... |
| CVE-2016-1605 | — | — | 3.8% | Aug 1, 2016 | Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 al... |
| CVE-2016-1461 | HIGH | 7.5 | 2.4% | Aug 1, 2016 | Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware dete... |
| CVE-2016-5005 | — | — | 4.8% | Jul 28, 2016 | Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators ... |
| CVE-2016-4469 | — | — | 7.9% | Jul 28, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to... |
| CVE-2016-4531 | — | — | 8.2% | Jul 28, 2016 | Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which ... |
| CVE-2016-4522 | — | — | 6.3% | Jul 28, 2016 | SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to ex... |
| CVE-2016-1467 | — | — | 0.6% | Jul 28, 2016 | Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) b... |
| CVE-2016-1465 | — | — | 0.9% | Jul 28, 2016 | Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a deni... |
| CVE-2016-1463 | — | — | 2.1% | Jul 28, 2016 | Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via cr... |
| CVE-2016-1462 | — | — | 1.0% | Jul 28, 2016 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0... |
| CVE-2016-1460 | — | — | 0.7% | Jul 28, 2016 | Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of ... |
| CVE-2016-1374 | — | — | 2.7% | Jul 28, 2016 | The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authentica... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now