2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-8742——The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t...
CVE-2016-5397——The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an e...
CVE-2016-10712——In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be...
CVE-2016-6169——Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ca...
CVE-2016-6168——Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ...
CVE-2016-2541——Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-2540——Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-3957——The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information ...
CVE-2016-3954——web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/sim...
CVE-2016-3953——The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors in...
CVE-2016-3952——web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values v...
CVE-2016-7394——tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
CVE-2016-0342——IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica...
CVE-2016-0329——Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10....
CVE-2016-0312——IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors relate...
CVE-2016-0311——Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6....
CVE-2016-0303——Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attacker...
CVE-2016-0300——IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attac...
CVE-2016-6599——BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService)...
CVE-2016-6598——BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on...
CVE-2016-10711——Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
CVE-2016-2983——IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read op...
CVE-2016-6217——Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject a...
CVE-2016-10710——Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential...
CVE-2016-5345——Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to g...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now