2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4996 | — | — | 0.3% | Jul 17, 2017 | discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root passwo... |
| CVE-2016-4984 | — | — | 0.1% | Jul 17, 2017 | /usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which a... |
| CVE-2016-4982 | — | — | 0.2% | Jul 17, 2017 | authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race conditio... |
| CVE-2016-10398 | — | — | 0.2% | Jul 17, 2017 | Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication token... |
| CVE-2016-8964 | — | — | 2.2% | Jul 13, 2017 | IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force... |
| CVE-2016-8952 | — | — | 0.7% | Jul 13, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This ... |
| CVE-2016-8951 | — | — | 2.9% | Jul 13, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack.... |
| CVE-2016-6019 | — | — | 0.7% | Jul 13, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This ... |
| CVE-2016-8953 | — | — | 0.7% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redi... |
| CVE-2016-8950 | — | — | 1.0% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2016-8948 | — | — | 0.7% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2016-8947 | — | — | 1.0% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redi... |
| CVE-2016-8946 | — | — | 0.7% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2016-6114 | — | — | 0.7% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2016-8638 | — | — | 2.1% | Jul 12, 2017 | A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that all... |
| CVE-2016-10397 | — | — | 1.9% | Jul 10, 2017 | In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used... |
| CVE-2016-4000 | — | — | 6.6% | Jul 6, 2017 | Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. |
| CVE-2016-10396 | — | — | 2.9% | Jul 6, 2017 | The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and ... |
| CVE-2016-9989 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9988 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9987 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9986 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9700 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack trace... |
| CVE-2016-9746 | — | — | 0.7% | Jul 5, 2017 | IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2016-9733 | — | — | 0.7% | Jul 5, 2017 | IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now