2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1866 | — | — | 1.5% | Apr 12, 2016 | Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle atta... |
| CVE-2016-0733 | — | — | 3.1% | Apr 12, 2016 | The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which ... |
| CVE-2016-3986 | — | — | 7.9% | Apr 12, 2016 | Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a... |
| CVE-2016-3985 | — | — | 1.2% | Apr 12, 2016 | The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS... |
| CVE-2016-1885 | — | — | 1.3% | Apr 12, 2016 | Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 ... |
| CVE-2016-0735 | — | — | 1.7% | Apr 11, 2016 | Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restr... |
| CVE-2016-3678 | — | — | 1.3% | Apr 11, 2016 | Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers... |
| CVE-2016-3676 | — | — | 0.3% | Apr 11, 2016 | Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to... |
| CVE-2016-3659 | — | — | 2.2% | Apr 11, 2016 | SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQ... |
| CVE-2016-3065 | — | — | 3.3% | Apr 11, 2016 | The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x befo... |
| CVE-2016-2385 | — | — | 30.5% | Apr 11, 2016 | Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER a... |
| CVE-2016-2193 | — | — | 1.8% | Apr 11, 2016 | PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow a... |
| CVE-2016-1235 | — | — | 3.4% | Apr 11, 2016 | The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and ... |
| CVE-2016-2393 | — | — | 0.3% | Apr 11, 2016 | Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) service... |
| CVE-2016-2171 | — | — | 42.7% | Apr 11, 2016 | The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, whic... |
| CVE-2016-2164 | — | — | 7.0% | Apr 11, 2016 | The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings be... |
| CVE-2016-2163 | — | — | 8.0% | Apr 11, 2016 | Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary... |
| CVE-2016-0784 | — | — | 56.3% | Apr 11, 2016 | Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 ... |
| CVE-2016-0783 | — | — | 7.1% | Apr 11, 2016 | The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes... |
| CVE-2016-0712 | — | — | 3.2% | Apr 11, 2016 | Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web... |
| CVE-2016-0711 | — | — | 3.1% | Apr 11, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arb... |
| CVE-2016-0710 | — | — | 52.4% | Apr 11, 2016 | Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker... |
| CVE-2016-0709 | — | — | 77.5% | Apr 11, 2016 | Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3... |
| CVE-2016-3984 | — | — | 1.1% | Apr 8, 2016 | The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.... |
| CVE-2016-3983 | — | — | 0.6% | Apr 8, 2016 | McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by levera... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now