2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0729 | — | — | 8.9% | Apr 7, 2016 | Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser ... |
| CVE-2016-1714 | — | — | 6.1% | Apr 7, 2016 | The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware... |
| CVE-2016-0734 | — | — | 8.3% | Apr 7, 2016 | The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, ... |
| CVE-2016-3948 | — | — | 35.3% | Apr 7, 2016 | Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause ... |
| CVE-2016-3947 | — | — | 14.4% | Apr 7, 2016 | Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and... |
| CVE-2016-7921 | — | — | — | Apr 7, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7921. Reason: This candidate is a duplicate of... |
| CVE-2016-1563 | — | — | 0.6% | Apr 7, 2016 | NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-... |
| CVE-2016-0888 | — | — | 3.1% | Apr 7, 2016 | EMC Documentum D2 before 4.6 lacks intended ACLs for configuration objects, which allows remote authenticated users to m... |
| CVE-2016-2277 | — | — | 0.9% | Apr 6, 2016 | IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remo... |
| CVE-2016-2272 | — | — | 1.2% | Apr 6, 2016 | Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified co... |
| CVE-2016-1346 | — | — | 1.6% | Apr 6, 2016 | The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remo... |
| CVE-2016-1313 | — | — | 3.0% | Apr 6, 2016 | Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunn... |
| CVE-2016-1291 | — | — | 6.8% | Apr 6, 2016 | Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote a... |
| CVE-2016-1290 | — | — | 1.5% | Apr 6, 2016 | The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2... |
| CVE-2016-1174 | — | — | 0.6% | Apr 6, 2016 | Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers... |
| CVE-2016-1173 | — | — | 1.0% | Apr 6, 2016 | Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inj... |
| CVE-2016-1172 | — | — | 0.6% | Apr 6, 2016 | Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers ... |
| CVE-2016-1171 | — | — | 1.0% | Apr 6, 2016 | Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inje... |
| CVE-2016-1170 | — | — | 0.6% | Apr 6, 2016 | Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers... |
| CVE-2016-1169 | — | — | 1.0% | Apr 6, 2016 | Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inj... |
| CVE-2016-0871 | — | — | 1.5% | Apr 6, 2016 | Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequentl... |
| CVE-2016-3969 | — | — | 1.0% | Apr 6, 2016 | Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enab... |
| CVE-2016-3968 | — | — | 1.4% | Apr 6, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 ... |
| CVE-2016-3118 | — | — | 1.2% | Apr 6, 2016 | CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8... |
| CVE-2016-3125 | — | — | 7.0% | Apr 5, 2016 | The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile direct... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now