2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-6806——Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover...
CVE-2016-4434——Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attacke...
CVE-2016-10512——MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP...
CVE-2016-5868——drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arb...
CVE-2016-8738——In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidato...
CVE-2016-6795——In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a speci...
CVE-2016-10511——The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/setting...
CVE-2016-8744——Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate th...
CVE-2016-8737——In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit...
CVE-2016-5759——The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator i...
CVE-2016-10405——Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attack...
CVE-2016-3086——The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential sto...
CVE-2016-1895——NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service v...
CVE-2016-5795——An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL...
CVE-2016-10510——Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inj...
CVE-2016-10509——SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCa...
CVE-2016-10508——Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitra...
CVE-2016-0713——Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scriptin...
CVE-2016-5001——This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circui...
CVE-2016-6800——The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate...
CVE-2016-4462——By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives t...
CVE-2016-10507——Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attac...
CVE-2016-10506——Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in Op...
CVE-2016-10505——NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, co...
CVE-2016-10504——Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now