2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-6806Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover...
CVE-2016-4434Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attacke...
CVE-2016-10512MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP...
CVE-2016-5868drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arb...
CVE-2016-8738In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidato...
CVE-2016-6795In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a speci...
CVE-2016-10511The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/setting...
CVE-2016-8744Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate th...
CVE-2016-8737In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit...
CVE-2016-5759The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator i...
CVE-2016-10405Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attack...
CVE-2016-3086The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential sto...
CVE-2016-1895NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service v...
CVE-2016-5795An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL...
CVE-2016-10510Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inj...
CVE-2016-10509SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCa...
CVE-2016-10508Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitra...
CVE-2016-0713Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scriptin...
CVE-2016-5001This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circui...
CVE-2016-6800The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate...
CVE-2016-4462By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives t...
CVE-2016-10507Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attac...
CVE-2016-10506Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in Op...
CVE-2016-10505NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, co...
CVE-2016-10504Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now