2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4059——Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute a...
CVE-2016-1596——Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authentic...
CVE-2016-1595——LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows rem...
CVE-2016-1594——Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request...
CVE-2016-1593——Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot...
CVE-2016-3145——Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021....
CVE-2016-2354——The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without...
CVE-2016-2306——The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext infor...
CVE-2016-2305——Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arb...
CVE-2016-2304——Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie,...
CVE-2016-2303——CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP ...
CVE-2016-2302——Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error...
CVE-2016-2301——SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbit...
CVE-2016-2300——Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages...
CVE-2016-2299——SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL c...
CVE-2016-3977——Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of ser...
CVE-2016-3190——The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to...
CVE-2016-6479——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6479. Reason: This candidate is a duplicate of...
CVE-2016-3466——Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 al...
CVE-2016-3465——Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via vectors relate...
CVE-2016-3464——Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 a...
CVE-2016-3463——Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 a...
CVE-2016-3462——Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Ne...
CVE-2016-3461——Unspecified vulnerability in the MySQL Enterprise Monitor component in Oracle MySQL 3.0.25 and earlier and 3.1.2 and ear...
CVE-2016-3460——Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote aut...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now