2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0405 | — | — | 0.3% | Jan 21, 2016 | Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4 allows local u... |
| CVE-2016-0404 | — | — | 1.5% | Jan 21, 2016 | Unspecified vulnerability in the Oracle Identity Federation component in Oracle Fusion Middleware 11.1.2.2 allows remote... |
| CVE-2016-0403 | — | — | 2.0% | Jan 21, 2016 | Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to... |
| CVE-2016-0402 | — | — | 4.6% | Jan 21, 2016 | Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Jav... |
| CVE-2016-0401 | — | — | 1.6% | Jan 21, 2016 | Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 all... |
| CVE-2016-1929 | — | — | 2.3% | Jan 20, 2016 | The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of... |
| CVE-2016-1928 | — | — | 6.2% | Jan 20, 2016 | Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execu... |
| CVE-2016-1901 | — | — | 3.8% | Jan 20, 2016 | Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impac... |
| CVE-2016-1900 | — | — | 1.9% | Jan 20, 2016 | CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote at... |
| CVE-2016-1899 | — | — | 1.9% | Jan 20, 2016 | CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP... |
| CVE-2016-1867 | — | — | 2.3% | Jan 20, 2016 | The jpc_pi_nextcprl function in JasPer 1.900.1 allows remote attackers to cause a denial of service (out-of-bounds read ... |
| CVE-2016-1296 | — | — | 2.1% | Jan 20, 2016 | The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows ... |
| CVE-2016-1907 | — | — | 14.3% | Jan 19, 2016 | The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of serv... |
| CVE-2016-1904 | — | — | 2.7% | Jan 19, 2016 | Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of se... |
| CVE-2016-1903 | — | — | 7.8% | Jan 19, 2016 | The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and... |
| CVE-2016-0201 | — | — | 2.0% | Jan 18, 2016 | GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials ... |
| CVE-2016-1295 | — | — | 2.0% | Jan 16, 2016 | Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyC... |
| CVE-2016-1294 | — | — | 1.1% | Jan 16, 2016 | Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote... |
| CVE-2016-1293 | — | — | 1.1% | Jan 16, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 an... |
| CVE-2016-1142 | — | — | 2.4% | Jan 16, 2016 | Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS comm... |
| CVE-2016-1133 | — | — | 1.5% | Jan 16, 2016 | CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0... |
| CVE-2016-1913 | — | — | 0.6% | Jan 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the Redhen module 7.x-1.x before 7.x-1.11 for Drupal allow remote... |
| CVE-2016-1912 | — | — | 1.4% | Jan 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject... |
| CVE-2016-1911 | — | — | 1.0% | Jan 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web ... |
| CVE-2016-1910 | — | — | 6.8% | Jan 15, 2016 | The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now