2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10365——Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link...
CVE-2016-10364——With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an...
CVE-2016-10363——Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, ...
CVE-2016-10362——Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file...
CVE-2016-1000222——Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas...
CVE-2016-1000221——Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co...
CVE-2016-1000220——Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr...
CVE-2016-1000219——Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul...
CVE-2016-1000218——Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup...
CVE-2016-10395——In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platfo...
CVE-2016-8751——Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Adm...
CVE-2016-8746——Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wi...
CVE-2016-10342——In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
CVE-2016-10341——In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
CVE-2016-10340——In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability e...
CVE-2016-10339——In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystor...
CVE-2016-10338——In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
CVE-2016-10337——In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
CVE-2016-10336——In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
CVE-2016-10335——In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
CVE-2016-10334——In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr...
CVE-2016-10333——In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
CVE-2016-10332——In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
CVE-2016-9984——IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the...
CVE-2016-9973——IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now