2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1357 | — | — | 1.1% | Mar 3, 2016 | The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4... |
| CVE-2016-1356 | — | — | 0.8% | Mar 3, 2016 | Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it e... |
| CVE-2016-1288 | — | — | 1.7% | Mar 3, 2016 | The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devic... |
| CVE-2016-1158 | — | — | 0.6% | Mar 3, 2016 | Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to... |
| CVE-2016-0227 | — | — | 0.9% | Mar 3, 2016 | Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BP... |
| CVE-2016-2842 | — | — | 53.7% | Mar 3, 2016 | The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify ... |
| CVE-2016-0799 | — | — | 32.4% | Mar 3, 2016 | The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates... |
| CVE-2016-0798 | — | — | 24.4% | Mar 3, 2016 | Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows re... |
| CVE-2016-0705 | — | — | 26.3% | Mar 3, 2016 | Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1... |
| CVE-2016-1355 | — | — | 0.8% | Mar 3, 2016 | Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT Syst... |
| CVE-2016-1354 | — | — | 0.8% | Mar 3, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows r... |
| CVE-2016-1329 | — | — | 3.7% | Mar 3, 2016 | Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on... |
| CVE-2016-8000 | — | — | — | Mar 3, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0800. Reason: This candidate is a duplicate of... |
| CVE-2016-2278 | — | — | 13.4% | Mar 2, 2016 | Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows... |
| CVE-2016-0704 | — | — | 6.9% | Mar 2, 2016 | An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL... |
| CVE-2016-0703 | — | — | 5.4% | Mar 2, 2016 | The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.... |
| CVE-2016-0800 | — | — | 82.1% | Mar 1, 2016 | The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to se... |
| CVE-2016-2562 | — | — | 0.8% | Mar 1, 2016 | The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificat... |
| CVE-2016-2561 | — | — | 2.5% | Mar 1, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow r... |
| CVE-2016-2560 | — | — | 3.1% | Mar 1, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5... |
| CVE-2016-2559 | — | — | 1.7% | Mar 1, 2016 | Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL p... |
| CVE-2016-1353 | — | — | 1.7% | Mar 1, 2016 | The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), an... |
| CVE-2016-0245 | — | — | 1.0% | Feb 29, 2016 | The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticat... |
| CVE-2016-0244 | — | — | 0.8% | Feb 29, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 C... |
| CVE-2016-0243 | — | — | 1.0% | Feb 29, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 C... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now