2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4326The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary cod...
CVE-2016-1421A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute co...
CVE-2016-1420The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3...
CVE-2016-1419Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload)...
CVE-2016-0916EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote a...
CVE-2016-0910EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI us...
CVE-2016-4449XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, ...
CVE-2016-4448CRITICAL9.8Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specif...
CVE-2016-4447The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denia...
CVE-2016-2150SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface p...
CVE-2016-1582LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which ...
CVE-2016-1581LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which a...
CVE-2016-0749The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or poss...
CVE-2016-4532Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2....
CVE-2016-4523HIGH7.5The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a...
CVE-2016-4510The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass ...
CVE-2016-4370HIGH8.8HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to ex...
CVE-2016-2310CRITICAL9.8General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000,...
CVE-2016-3738Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated user...
CVE-2016-3711HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of...
CVE-2016-3708Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally...
CVE-2016-3703Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is grant...
CVE-2016-2160Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root pri...
CVE-2016-2149Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the...
CVE-2016-2142Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configurat...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now