2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-2000——HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute a...
CVE-2016-1177——The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows rem...
CVE-2016-1789——Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an...
CVE-2016-1176——Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a cra...
CVE-2016-1175——Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remo...
CVE-2016-0289——shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4...
CVE-2016-2343——Patterson Dental Eaglesoft 17 has a hardcoded password of sql for the dba account, which allows remote attackers to obta...
CVE-2016-2289——Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, a...
CVE-2016-0793——Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se...
CVE-2016-1168——Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows rem...
CVE-2016-1167——Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authe...
CVE-2016-1345——Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote a...
CVE-2016-3142——The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remot...
CVE-2016-3141——Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote ...
CVE-2016-2288——Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file...
CVE-2016-1760——The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restric...
CVE-2016-3679——Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allo...
CVE-2016-1650——The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in...
CVE-2016-1649——The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does...
CVE-2016-1648——Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions ...
CVE-2016-1647——Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widge...
CVE-2016-2344——Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier a...
CVE-2016-1314——Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authe...
CVE-2016-0226——The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (...
CVE-2016-3119——The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now