2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7035HIGH8.8An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attack...
CVE-2016-7078MEDIUM4.3foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u...
CVE-2016-7077MEDIUM4.3foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt...
CVE-2016-7071HIGH8.8It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passe...
CVE-2016-7075HIGH7.5It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate cert...
CVE-2016-7067MEDIUM6.5Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an...
CVE-2016-9044HIGH8.8An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 ...
CVE-2016-9040MEDIUM5.5An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerab...
CVE-2016-1000232NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header pars...
CVE-2016-1000030Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of retu...
CVE-2016-0373LOW3.1IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST...
CVE-2016-0234MEDIUM4IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous us...
CVE-2016-0205LOW3.3A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacke...
CVE-2016-9605MEDIUM6.1A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnera...
CVE-2016-7048HIGH8.1The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote at...
CVE-2016-9598MEDIUM6.5libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of...
CVE-2016-9596MEDIUM6.5libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a...
CVE-2016-9140Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-4975Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigat...
CVE-2016-2922LOW3.7IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SS...
CVE-2016-8527Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th...
CVE-2016-8526Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a...
CVE-2016-4406A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all ver...
CVE-2016-4405A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collec...
CVE-2016-4404A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now