2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10512 | — | — | 2.1% | Sep 30, 2017 | MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP... |
| CVE-2016-5868 | — | — | 1.4% | Sep 25, 2017 | drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arb... |
| CVE-2016-8738 | — | — | 3.3% | Sep 20, 2017 | In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidato... |
| CVE-2016-6795 | — | — | 8.4% | Sep 20, 2017 | In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a speci... |
| CVE-2016-10511 | — | — | 0.8% | Sep 18, 2017 | The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/setting... |
| CVE-2016-8744 | — | — | 3.8% | Sep 13, 2017 | Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate th... |
| CVE-2016-8737 | — | — | 1.3% | Sep 13, 2017 | In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit... |
| CVE-2016-5759 | — | — | 0.4% | Sep 8, 2017 | The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator i... |
| CVE-2016-10405 | — | — | 1.9% | Sep 7, 2017 | Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attack... |
| CVE-2016-0732 | HIGH | 8.8 | 1.2% | Sep 7, 2017 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 th... |
| CVE-2016-3086 | — | — | 3.6% | Sep 5, 2017 | The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential sto... |
| CVE-2016-1895 | — | — | 1.5% | Sep 1, 2017 | NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service v... |
| CVE-2016-5795 | — | — | 2.2% | Aug 31, 2017 | An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL... |
| CVE-2016-10510 | — | — | 1.7% | Aug 31, 2017 | Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inj... |
| CVE-2016-10509 | — | — | 1.4% | Aug 31, 2017 | SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCa... |
| CVE-2016-10508 | — | — | 0.8% | Aug 31, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitra... |
| CVE-2016-0713 | — | — | 0.5% | Aug 31, 2017 | Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scriptin... |
| CVE-2016-5001 | — | — | 0.6% | Aug 30, 2017 | This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circui... |
| CVE-2016-6800 | — | — | 3.1% | Aug 30, 2017 | The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate... |
| CVE-2016-4462 | — | — | 3.8% | Aug 30, 2017 | By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives t... |
| CVE-2016-10507 | — | — | 2.1% | Aug 30, 2017 | Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attac... |
| CVE-2016-10506 | — | — | 3.5% | Aug 30, 2017 | Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in Op... |
| CVE-2016-10505 | — | — | 2.1% | Aug 30, 2017 | NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, co... |
| CVE-2016-10504 | — | — | 8.3% | Aug 30, 2017 | Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote... |
| CVE-2016-2980 | — | — | 1.0% | Aug 29, 2017 | The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own scr... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now