2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10365 | — | — | 1.0% | Jun 16, 2017 | Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link... |
| CVE-2016-10364 | — | — | 1.0% | Jun 16, 2017 | With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an... |
| CVE-2016-10363 | — | — | 1.3% | Jun 16, 2017 | Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, ... |
| CVE-2016-10362 | — | — | 1.1% | Jun 16, 2017 | Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file... |
| CVE-2016-1000222 | — | — | 1.1% | Jun 16, 2017 | Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas... |
| CVE-2016-1000221 | — | — | 1.8% | Jun 16, 2017 | Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co... |
| CVE-2016-1000220 | — | — | 1.1% | Jun 16, 2017 | Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr... |
| CVE-2016-1000219 | — | — | 2.0% | Jun 16, 2017 | Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul... |
| CVE-2016-1000218 | — | — | 0.8% | Jun 16, 2017 | Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup... |
| CVE-2016-10395 | — | — | 0.4% | Jun 15, 2017 | In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platfo... |
| CVE-2016-8751 | — | — | 2.1% | Jun 14, 2017 | Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Adm... |
| CVE-2016-8746 | — | — | 2.7% | Jun 14, 2017 | Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wi... |
| CVE-2016-10342 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler. |
| CVE-2016-10341 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended. |
| CVE-2016-10340 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability e... |
| CVE-2016-10339 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystor... |
| CVE-2016-10338 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing. |
| CVE-2016-10337 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed. |
| CVE-2016-10336 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot. |
| CVE-2016-10335 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. |
| CVE-2016-10334 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr... |
| CVE-2016-10333 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. |
| CVE-2016-10332 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications. |
| CVE-2016-9984 | — | — | 1.6% | Jun 13, 2017 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the... |
| CVE-2016-9973 | — | — | 0.7% | Jun 13, 2017 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now