2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-8742The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t...
CVE-2016-5397The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an e...
CVE-2016-10712In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be...
CVE-2016-6169Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ca...
CVE-2016-6168Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ...
CVE-2016-2541Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-2540Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-3957The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information ...
CVE-2016-3954web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/sim...
CVE-2016-3953The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors in...
CVE-2016-3952web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values v...
CVE-2016-7394tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
CVE-2016-0342IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica...
CVE-2016-0329Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10....
CVE-2016-0312IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors relate...
CVE-2016-0311Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6....
CVE-2016-0303Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attacker...
CVE-2016-0300IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attac...
CVE-2016-6599BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService)...
CVE-2016-6598BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on...
CVE-2016-10711Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
CVE-2016-2983IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read op...
CVE-2016-6217Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject a...
CVE-2016-10710Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential...
CVE-2016-5345Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to g...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now