2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-0871Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequentl...
CVE-2016-3969Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enab...
CVE-2016-3968Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 ...
CVE-2016-3118CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8...
CVE-2016-3125The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile direct...
CVE-2016-2000HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute a...
CVE-2016-1177The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows rem...
CVE-2016-1789Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an...
CVE-2016-1176Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a cra...
CVE-2016-1175Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remo...
CVE-2016-0289shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4...
CVE-2016-2343Patterson Dental Eaglesoft 17 has a hardcoded password of sql for the dba account, which allows remote attackers to obta...
CVE-2016-2289Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, a...
CVE-2016-0793Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se...
CVE-2016-1168Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows rem...
CVE-2016-1167Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authe...
CVE-2016-1345Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote a...
CVE-2016-3142The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remot...
CVE-2016-3141Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote ...
CVE-2016-2288Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file...
CVE-2016-1760The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restric...
CVE-2016-3679Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allo...
CVE-2016-1650The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in...
CVE-2016-1649The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does...
CVE-2016-1648Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now