2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10365Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link...
CVE-2016-10364With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an...
CVE-2016-10363Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, ...
CVE-2016-10362Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file...
CVE-2016-1000222Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas...
CVE-2016-1000221Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co...
CVE-2016-1000220Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr...
CVE-2016-1000219Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul...
CVE-2016-1000218Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup...
CVE-2016-10395In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platfo...
CVE-2016-8751Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Adm...
CVE-2016-8746Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wi...
CVE-2016-10342In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
CVE-2016-10341In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
CVE-2016-10340In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability e...
CVE-2016-10339In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystor...
CVE-2016-10338In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
CVE-2016-10337In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
CVE-2016-10336In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
CVE-2016-10335In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
CVE-2016-10334In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr...
CVE-2016-10333In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
CVE-2016-10332In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
CVE-2016-9984IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the...
CVE-2016-9973IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now