2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7035 | HIGH | 8.8 | 0.4% | Sep 10, 2018 | An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attack... |
| CVE-2016-7078 | MEDIUM | 4.3 | 1.4% | Sep 10, 2018 | foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u... |
| CVE-2016-7077 | MEDIUM | 4.3 | 1.4% | Sep 10, 2018 | foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt... |
| CVE-2016-7071 | HIGH | 8.8 | 2.2% | Sep 10, 2018 | It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passe... |
| CVE-2016-7075 | HIGH | 7.5 | 1.6% | Sep 10, 2018 | It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate cert... |
| CVE-2016-7067 | MEDIUM | 6.5 | 0.9% | Sep 10, 2018 | Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an... |
| CVE-2016-9044 | HIGH | 8.8 | 3.8% | Sep 7, 2018 | An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 ... |
| CVE-2016-9040 | MEDIUM | 5.5 | 0.5% | Sep 7, 2018 | An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerab... |
| CVE-2016-1000232 | — | — | 2.4% | Sep 5, 2018 | NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header pars... |
| CVE-2016-1000030 | — | — | 1.8% | Sep 5, 2018 | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of retu... |
| CVE-2016-0373 | LOW | 3.1 | 0.8% | Aug 30, 2018 | IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST... |
| CVE-2016-0234 | MEDIUM | 4 | 0.3% | Aug 30, 2018 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous us... |
| CVE-2016-0205 | LOW | 3.3 | 0.4% | Aug 30, 2018 | A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacke... |
| CVE-2016-9605 | MEDIUM | 6.1 | 0.8% | Aug 22, 2018 | A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnera... |
| CVE-2016-7048 | HIGH | 8.1 | 4.9% | Aug 20, 2018 | The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote at... |
| CVE-2016-9598 | MEDIUM | 6.5 | 1.0% | Aug 16, 2018 | libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of... |
| CVE-2016-9596 | MEDIUM | 6.5 | 0.9% | Aug 16, 2018 | libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a... |
| CVE-2016-9140 | — | — | — | Aug 15, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-4975 | — | — | 19.8% | Aug 14, 2018 | Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigat... |
| CVE-2016-2922 | LOW | 3.7 | 0.7% | Aug 13, 2018 | IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SS... |
| CVE-2016-8527 | — | — | 13.2% | Aug 6, 2018 | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th... |
| CVE-2016-8526 | — | — | 9.8% | Aug 6, 2018 | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a... |
| CVE-2016-4406 | — | — | 2.6% | Aug 6, 2018 | A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all ver... |
| CVE-2016-4405 | — | — | 4.8% | Aug 6, 2018 | A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collec... |
| CVE-2016-4404 | — | — | 14.8% | Aug 6, 2018 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now