2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1917 | — | — | 1.0% | Apr 22, 2016 | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.... |
| CVE-2016-1916 | — | — | 0.8% | Apr 22, 2016 | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.... |
| CVE-2016-1036 | — | — | 1.6% | Apr 22, 2016 | Cross-site scripting (XSS) vulnerability in Adobe Analytics AppMeasurement for Flash Library before 4.0.1, when debugTra... |
| CVE-2016-4065 | — | — | 2.7% | Apr 22, 2016 | The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows r... |
| CVE-2016-4064 | — | — | 4.2% | Apr 22, 2016 | Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Wind... |
| CVE-2016-4063 | — | — | 4.5% | Apr 22, 2016 | Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute a... |
| CVE-2016-4062 | — | — | 1.4% | Apr 22, 2016 | Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote att... |
| CVE-2016-4061 | — | — | 1.3% | Apr 22, 2016 | Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application cra... |
| CVE-2016-4060 | — | — | 1.3% | Apr 22, 2016 | Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a d... |
| CVE-2016-4059 | — | — | 4.4% | Apr 22, 2016 | Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute a... |
| CVE-2016-1596 | — | — | 2.4% | Apr 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authentic... |
| CVE-2016-1595 | — | — | 6.6% | Apr 22, 2016 | LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows rem... |
| CVE-2016-1594 | — | — | 6.9% | Apr 22, 2016 | Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request... |
| CVE-2016-1593 | — | — | 64.1% | Apr 22, 2016 | Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot... |
| CVE-2016-3145 | — | — | 0.3% | Apr 22, 2016 | Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.... |
| CVE-2016-2354 | — | — | 1.1% | Apr 22, 2016 | The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without... |
| CVE-2016-2306 | — | — | 1.9% | Apr 22, 2016 | The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext infor... |
| CVE-2016-2305 | — | — | 0.9% | Apr 22, 2016 | Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arb... |
| CVE-2016-2304 | — | — | 1.1% | Apr 22, 2016 | Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie,... |
| CVE-2016-2303 | — | — | 1.1% | Apr 22, 2016 | CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP ... |
| CVE-2016-2302 | — | — | 1.2% | Apr 22, 2016 | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error... |
| CVE-2016-2301 | — | — | 0.8% | Apr 22, 2016 | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbit... |
| CVE-2016-2300 | — | — | 1.2% | Apr 22, 2016 | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages... |
| CVE-2016-2299 | — | — | 1.4% | Apr 22, 2016 | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL c... |
| CVE-2016-3977 | — | — | 2.1% | Apr 21, 2016 | Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of ser... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now