2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10567product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all t...
CVE-2016-10566install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download bi...
CVE-2016-10559selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-downloa...
CVE-2016-10558aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP,...
CVE-2016-10556sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10551waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterli...
CVE-2016-10525When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby peo...
CVE-2016-7076MEDIUM6.4sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo execut...
CVE-2016-8656HIGH7Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script ...
CVE-2016-8627MEDIUM4.3admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that all...
CVE-2016-9335A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches runn...
CVE-2016-10722CRITICAL9.8partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient vali...
CVE-2016-10721partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validat...
CVE-2016-10036Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to...
CVE-2016-9602HIGH7.6Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside...
CVE-2016-9590MEDIUM6.5puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform direc...
CVE-2016-9043HIGH7.8An out of bound write vulnerability exists in the EMF parsing functionality of CorelDRAW X8 (CdrGfx - Corel Graphics Eng...
CVE-2016-9038HIGH7.8An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A sp...
CVE-2016-8732HIGH7.8Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. We...
CVE-2016-8730HIGH7.8An of bound write / memory corruption vulnerability exists in the GIF parsing functionality of Core PHOTO-PAINT X8 18.1....
CVE-2016-8729HIGH7.8An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF ...
CVE-2016-8728HIGH7.8An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A...
CVE-2016-8384HIGH8.8An exploitable heap corruption vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter.
CVE-2016-8383HIGH8.8An exploitable heap corruption vulnerability exists in the Doc_GetFontTable functionality of AntennaHouse DMC HTMLFilter...
CVE-2016-8382HIGH8.3An exploitable heap corruption vulnerability exists in the Doc_SetSummary functionality of AntennaHouse DMC HTMLFilter. ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now