2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4480 | — | — | 0.5% | May 18, 2016 | The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Si... |
| CVE-2016-2077 | — | — | 1.8% | May 18, 2016 | VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable fil... |
| CVE-2016-0731 | — | — | 2.6% | May 18, 2016 | The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files v... |
| CVE-2016-0707 | — | — | 0.4% | May 18, 2016 | The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/am... |
| CVE-2016-3719 | — | — | — | May 17, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-2189 | — | — | — | May 17, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4565. Reason: This candidate is a reservation ... |
| CVE-2016-4425 | MEDIUM | 6.5 | 1.9% | May 17, 2016 | Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumpti... |
| CVE-2016-3727 | — | — | 2.2% | May 17, 2016 | The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users wit... |
| CVE-2016-3726 | — | — | 2.3% | May 17, 2016 | Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect u... |
| CVE-2016-3725 | — | — | 2.3% | May 17, 2016 | Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata ... |
| CVE-2016-3724 | — | — | 2.1% | May 17, 2016 | Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive... |
| CVE-2016-3723 | — | — | 1.9% | May 17, 2016 | Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin i... |
| CVE-2016-3722 | — | — | 2.2% | May 17, 2016 | Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of s... |
| CVE-2016-3721 | MEDIUM | 4.3 | 2.1% | May 17, 2016 | Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters in... |
| CVE-2016-3705 | — | — | 5.1% | May 17, 2016 | The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep... |
| CVE-2016-3674 | HIGH | 7.5 | 8.4% | May 17, 2016 | Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Drive... |
| CVE-2016-3627 | HIGH | 7.5 | 7.1% | May 17, 2016 | The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dep... |
| CVE-2016-0323 | — | — | 0.8% | May 17, 2016 | The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to ... |
| CVE-2016-0306 | — | — | 1.4% | May 17, 2016 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-... |
| CVE-2016-3185 | — | — | 3.1% | May 16, 2016 | The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.1... |
| CVE-2016-2554 | — | — | 11.0% | May 16, 2016 | Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows rem... |
| CVE-2016-0390 | — | — | 0.6% | May 15, 2016 | Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 al... |
| CVE-2016-0381 | — | — | 1.0% | May 15, 2016 | IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated... |
| CVE-2016-0341 | — | — | 1.4% | May 15, 2016 | IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do ... |
| CVE-2016-1671 | — | — | 1.6% | May 14, 2016 | Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now