2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8513A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The proble...
CVE-2016-8512A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.
CVE-2016-8511A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x,...
CVE-2016-10713An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly le...
CVE-2016-9570cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer de...
CVE-2016-9569The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of servic...
CVE-2016-8742The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t...
CVE-2016-5397The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an e...
CVE-2016-10712In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be...
CVE-2016-6169Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ca...
CVE-2016-6168Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ...
CVE-2016-2541Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-2540Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-3957The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information ...
CVE-2016-3954web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/sim...
CVE-2016-3953The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors in...
CVE-2016-3952web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values v...
CVE-2016-7394tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
CVE-2016-6813CRITICAL9.8Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer ...
CVE-2016-0342IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica...
CVE-2016-0329Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10....
CVE-2016-0312IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors relate...
CVE-2016-0311Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6....
CVE-2016-0303Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attacker...
CVE-2016-0300IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attac...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now