2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-8513 | — | — | 0.7% | Feb 15, 2018 | A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The proble... |
| CVE-2016-8512 | — | — | 5.6% | Feb 15, 2018 | A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found. |
| CVE-2016-8511 | — | — | 15.6% | Feb 15, 2018 | A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x,... |
| CVE-2016-10713 | — | — | 1.6% | Feb 13, 2018 | An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly le... |
| CVE-2016-9570 | — | — | 1.0% | Feb 12, 2018 | cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer de... |
| CVE-2016-9569 | — | — | 0.3% | Feb 12, 2018 | The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of servic... |
| CVE-2016-8742 | — | — | 2.0% | Feb 12, 2018 | The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t... |
| CVE-2016-5397 | — | — | 7.1% | Feb 12, 2018 | The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an e... |
| CVE-2016-10712 | — | — | 2.3% | Feb 9, 2018 | In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be... |
| CVE-2016-6169 | — | — | 5.3% | Feb 7, 2018 | Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ca... |
| CVE-2016-6168 | — | — | 3.3% | Feb 7, 2018 | Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ... |
| CVE-2016-2541 | — | — | 1.2% | Feb 7, 2018 | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via... |
| CVE-2016-2540 | — | — | 1.9% | Feb 7, 2018 | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via... |
| CVE-2016-3957 | — | — | 5.0% | Feb 6, 2018 | The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information ... |
| CVE-2016-3954 | — | — | 1.4% | Feb 6, 2018 | web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/sim... |
| CVE-2016-3953 | — | — | 3.4% | Feb 6, 2018 | The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors in... |
| CVE-2016-3952 | — | — | 1.1% | Feb 6, 2018 | web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values v... |
| CVE-2016-7394 | — | — | 0.6% | Feb 6, 2018 | tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie. |
| CVE-2016-6813 | CRITICAL | 9.8 | 5.6% | Feb 6, 2018 | Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer ... |
| CVE-2016-0342 | — | — | 0.7% | Feb 2, 2018 | IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica... |
| CVE-2016-0329 | — | — | 0.7% | Feb 2, 2018 | Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.... |
| CVE-2016-0312 | — | — | 1.7% | Feb 2, 2018 | IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors relate... |
| CVE-2016-0311 | — | — | 0.9% | Feb 2, 2018 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.... |
| CVE-2016-0303 | — | — | 0.6% | Feb 2, 2018 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attacker... |
| CVE-2016-0300 | — | — | 0.8% | Feb 2, 2018 | IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attac... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now