2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5402HIGH8.8A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, auth...
CVE-2016-2121MEDIUM4A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potential...
CVE-2016-10734ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
CVE-2016-10733ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
CVE-2016-10732ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.ph...
CVE-2016-10731ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-fil...
CVE-2016-10730An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. A...
CVE-2016-10729An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. T...
CVE-2016-9069A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. T...
CVE-2016-7475Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkerne...
CVE-2016-9045HIGH8.8A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request...
CVE-2016-0715Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vuln...
CVE-2016-7066It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform befor...
CVE-2016-7074MEDIUM5.3An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in...
CVE-2016-7073MEDIUM5.3An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in...
CVE-2016-7070HIGH8A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it in...
CVE-2016-7069MEDIUM5.9An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a b...
CVE-2016-7068MEDIUM5.3An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a re...
CVE-2016-7047MEDIUM4.3A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReport...
CVE-2016-0750MEDIUM4.2The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain...
CVE-2016-7072MEDIUM5.3An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated atta...
CVE-2016-9048HIGH7.4Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially c...
CVE-2016-7061LOW3.5An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discover...
CVE-2016-7056MEDIUM5.5A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recov...
CVE-2016-7041MEDIUM6.5Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to b...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now