2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4328——MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which m...
CVE-2016-4326——The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary cod...
CVE-2016-1421——A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute co...
CVE-2016-1420——The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3...
CVE-2016-1419——Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload)...
CVE-2016-0916——EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote a...
CVE-2016-0910——EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI us...
CVE-2016-4449——XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, ...
CVE-2016-4448CRITICAL9.8Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specif...
CVE-2016-4447——The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denia...
CVE-2016-2150——SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface p...
CVE-2016-1582——LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which ...
CVE-2016-1581——LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which a...
CVE-2016-0749——The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or poss...
CVE-2016-4532——Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2....
CVE-2016-4523HIGH7.5The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a...
CVE-2016-4510——The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass ...
CVE-2016-4370HIGH8.8HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to ex...
CVE-2016-2310CRITICAL9.8General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000,...
CVE-2016-3738——Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated user...
CVE-2016-3711——HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of...
CVE-2016-3708——Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally...
CVE-2016-3703——Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is grant...
CVE-2016-2160——Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root pri...
CVE-2016-2149——Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now