2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1000343In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if us...
CVE-2016-1000342In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on ...
CVE-2016-1000341In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Wher...
CVE-2016-1000340In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of...
CVE-2016-1000339In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due ...
CVE-2016-1000338HIGH7.5In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on ve...
CVE-2016-10634scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which l...
CVE-2016-10633dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which l...
CVE-2016-10632apk-parser2 is a module which extracts Android Manifest info from an APK file. apk-parser2 downloads binary resources ov...
CVE-2016-10631jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTT...
CVE-2016-10630install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
CVE-2016-10629nw-with-arm is a NW Installer including ARM-Build. nw-with-arm downloads binary resources over HTTP, which leaves it vul...
CVE-2016-10628selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads b...
CVE-2016-10626mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulne...
CVE-2016-10625headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-brow...
CVE-2016-10624selenium-chromedriver is a simple utility for downloading the Selenium Webdriver for Google Chrome selenium-chromedriver...
CVE-2016-10623macaca-chromedriver-zxa is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver-zxa downloads binary res...
CVE-2016-10622nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which le...
CVE-2016-10621fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which l...
CVE-2016-10620atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resource...
CVE-2016-10619pennyworth is a natural language templating engine. pennyworth downloads data resources over HTTP, which leaves it vulne...
CVE-2016-10618node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to...
CVE-2016-10617box2d-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cau...
CVE-2016-10616openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resource...
CVE-2016-10615curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now