2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9573MEDIUM6.5An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafte...
CVE-2016-8625MEDIUM5.3curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users...
CVE-2016-8623LOW3.3A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-afte...
CVE-2016-8620MEDIUM6.5The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read vi...
CVE-2016-8619MEDIUM5.3The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
CVE-2016-8616LOW3.7A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons o...
CVE-2016-8615MEDIUM5.3A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back ...
CVE-2016-8621MEDIUM5.3The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input...
CVE-2016-8617LOW3.3The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if ...
CVE-2016-8624MEDIUM5.3curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with ...
CVE-2016-8622LOW3.7The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if th...
CVE-2016-8618MEDIUM5.3The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to a...
CVE-2016-8614MEDIUM6.3A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing...
CVE-2016-8631MEDIUM6.3The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with acc...
CVE-2016-8628HIGH7.6Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker wit...
CVE-2016-8613MEDIUM6.4A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. ...
CVE-2016-8611MEDIUM4.3A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2...
CVE-2016-8657It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/s...
CVE-2016-8626MEDIUM6.5A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an au...
CVE-2016-9597It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix ...
CVE-2016-9603MEDIUM5.5A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; t...
CVE-2016-9578HIGH7.5A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to...
CVE-2016-9577HIGH7.5A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker coul...
CVE-2016-9595HIGH7.3A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A loca...
CVE-2016-9258Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now