2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3019 | — | — | 0.8% | Jun 7, 2017 | IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacke... |
| CVE-2016-0254 | — | — | 1.9% | Jun 7, 2017 | IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity In... |
| CVE-2016-9834 | — | — | 1.8% | Jun 7, 2017 | An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph... |
| CVE-2016-9961 | — | — | 4.4% | Jun 6, 2017 | game-music-emu before 0.6.1 mishandles unspecified integer values. |
| CVE-2016-9960 | — | — | 0.5% | Jun 6, 2017 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). |
| CVE-2016-5004 | — | — | 6.4% | Jun 6, 2017 | The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a... |
| CVE-2016-3077 | — | — | 1.0% | Jun 6, 2017 | The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of ... |
| CVE-2016-3066 | — | — | 1.0% | Jun 6, 2017 | The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard. |
| CVE-2016-0768 | — | — | 1.4% | Jun 6, 2017 | PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. |
| CVE-2016-0726 | — | — | 2.3% | Jun 6, 2017 | The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which ... |
| CVE-2016-10297 | — | — | 0.3% | Jun 6, 2017 | In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnera... |
| CVE-2016-8231 | — | — | 0.5% | Jun 4, 2017 | In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certifica... |
| CVE-2016-8230 | — | — | 1.1% | Jun 4, 2017 | In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, mach... |
| CVE-2016-8229 | — | — | 0.5% | Jun 4, 2017 | A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker w... |
| CVE-2016-8228 | — | — | 0.4% | Jun 4, 2017 | In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrati... |
| CVE-2016-3073 | — | — | — | Jun 1, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3079. Reason: This candidate is a reservation ... |
| CVE-2016-10373 | — | — | — | May 31, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10214. Reason: This candidate is a reservation... |
| CVE-2016-3083 | — | — | 1.0% | May 30, 2017 | Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). W... |
| CVE-2016-10379 | — | — | 1.7% | May 29, 2017 | The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators v... |
| CVE-2016-10378 | — | — | 1.3% | May 29, 2017 | e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.ph... |
| CVE-2016-10377 | — | — | 0.9% | May 29, 2017 | In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to... |
| CVE-2016-10376 | — | — | 1.2% | May 28, 2017 | Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused... |
| CVE-2016-8497 | — | — | — | May 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2016-8496 | — | — | — | May 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2016-10375 | — | — | 2.2% | May 26, 2017 | Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now