2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6256 | — | — | 7.9% | May 26, 2017 | SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML ... |
| CVE-2016-5007 | — | — | 2.8% | May 25, 2017 | Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mapping... |
| CVE-2016-4977 | — | — | 79.2% | May 25, 2017 | When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1... |
| CVE-2016-4435 | — | — | 0.9% | May 25, 2017 | An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow un... |
| CVE-2016-3084 | — | — | 1.2% | May 25, 2017 | The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions,... |
| CVE-2016-0781 | — | — | 0.7% | May 25, 2017 | The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0... |
| CVE-2016-7979 | — | — | 6.5% | May 23, 2017 | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently exec... |
| CVE-2016-7978 | — | — | 5.5% | May 23, 2017 | Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors rela... |
| CVE-2016-7977 | — | — | 4.6% | May 23, 2017 | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read... |
| CVE-2016-5735 | — | — | 1.8% | May 23, 2017 | Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have ... |
| CVE-2016-5178 | — | — | 1.8% | May 23, 2017 | Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of s... |
| CVE-2016-5177 | — | — | 1.3% | May 23, 2017 | Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of se... |
| CVE-2016-1876 | — | — | 0.3% | May 23, 2017 | The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privil... |
| CVE-2016-10073 | — | — | 83.6% | May 23, 2017 | The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai... |
| CVE-2016-6112 | — | — | 1.0% | May 22, 2017 | IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate t... |
| CVE-2016-2172 | — | — | — | May 22, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-7804 | — | — | 1.8% | May 22, 2017 | Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges vi... |
| CVE-2016-4905 | — | — | 1.9% | May 22, 2017 | SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allo... |
| CVE-2016-4904 | — | — | 0.9% | May 22, 2017 | Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions pri... |
| CVE-2016-4903 | — | — | 1.2% | May 22, 2017 | Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 a... |
| CVE-2016-4901 | — | — | 1.5% | May 22, 2017 | Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain priv... |
| CVE-2016-4900 | — | — | 1.5% | May 22, 2017 | Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privil... |
| CVE-2016-4863 | — | — | 0.7% | May 22, 2017 | The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Cla... |
| CVE-2016-4854 | — | — | 1.0% | May 22, 2017 | Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijac... |
| CVE-2016-3403 | — | — | 1.4% | May 17, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Pat... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now