2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-1866Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle atta...
CVE-2016-0733The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which ...
CVE-2016-3986Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a...
CVE-2016-3985The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS...
CVE-2016-1885Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 ...
CVE-2016-0735Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restr...
CVE-2016-3678Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers...
CVE-2016-3676Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to...
CVE-2016-3659SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQ...
CVE-2016-3065The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x befo...
CVE-2016-2385Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER a...
CVE-2016-2193PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow a...
CVE-2016-1235The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and ...
CVE-2016-2393Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) service...
CVE-2016-2171The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, whic...
CVE-2016-2164The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings be...
CVE-2016-2163Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary...
CVE-2016-0784Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 ...
CVE-2016-0783The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes...
CVE-2016-0712Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web...
CVE-2016-0711Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arb...
CVE-2016-0710Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker...
CVE-2016-0709Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3...
CVE-2016-3984The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0....
CVE-2016-3983McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by levera...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now