2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1136Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to in...
CVE-2016-0867CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.
CVE-2016-1488Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices be...
CVE-2016-1304Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitr...
CVE-2016-1303The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a craf...
CVE-2016-1493Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middl...
CVE-2016-0756The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields whe...
CVE-2016-0755The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy co...
CVE-2016-0754cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a differe...
CVE-2016-0738OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close serv...
CVE-2016-0737OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers ...
CVE-2016-1882FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel ...
CVE-2016-1879The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, w...
CVE-2016-3197Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-3197. Reason: This candidate is a duplicate of...
CVE-2016-0868Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 1...
CVE-2016-1300Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject a...
CVE-2016-1299The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a d...
CVE-2016-2047The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x b...
CVE-2016-1983The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (inv...
CVE-2016-1982The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a den...
CVE-2016-1924The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds rea...
CVE-2016-1923Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to ca...
CVE-2016-1896Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.04...
CVE-2016-0209Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arb...
CVE-2016-1926Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 all...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now