2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5864 | — | — | 0.6% | Aug 16, 2017 | In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some para... |
| CVE-2016-5863 | — | — | 0.5% | Aug 16, 2017 | In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity ch... |
| CVE-2016-5862 | — | — | 0.5% | Aug 16, 2017 | When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for M... |
| CVE-2016-5861 | — | — | 0.4% | Aug 16, 2017 | In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable contro... |
| CVE-2016-5860 | — | — | 0.6% | Aug 16, 2017 | In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is c... |
| CVE-2016-5859 | — | — | 0.6% | Aug 16, 2017 | In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is ca... |
| CVE-2016-5858 | — | — | 0.5% | Aug 16, 2017 | In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplie... |
| CVE-2016-5855 | — | — | 0.5% | Aug 16, 2017 | In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is... |
| CVE-2016-5854 | — | — | 0.5% | Aug 16, 2017 | In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be... |
| CVE-2016-5853 | — | — | 0.8% | Aug 16, 2017 | In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check e... |
| CVE-2016-5347 | — | — | 0.5% | Aug 16, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to users... |
| CVE-2016-6029 | — | — | 1.2% | Aug 14, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive inform... |
| CVE-2016-6021 | — | — | 0.5% | Aug 14, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerabilit... |
| CVE-2016-6796 | HIGH | 7.5 | 8.3% | Aug 11, 2017 | A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to... |
| CVE-2016-8745 | — | — | 16.0% | Aug 10, 2017 | A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5... |
| CVE-2016-6817 | HIGH | 7.5 | 7.2% | Aug 10, 2017 | The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header ... |
| CVE-2016-6797 | HIGH | 7.5 | 8.1% | Aug 10, 2017 | The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0... |
| CVE-2016-8739 | — | — | 7.3% | Aug 10, 2017 | The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyRea... |
| CVE-2016-6812 | — | — | 8.1% | Aug 10, 2017 | The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to prov... |
| CVE-2016-6794 | MEDIUM | 5.3 | 7.2% | Aug 10, 2017 | When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the ... |
| CVE-2016-5018 | CRITICAL | 9.1 | 10.3% | Aug 10, 2017 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malici... |
| CVE-2016-0762 | MEDIUM | 5.9 | 7.7% | Aug 10, 2017 | The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to ... |
| CVE-2016-8949 | — | — | 0.7% | Aug 9, 2017 | IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, ... |
| CVE-2016-6121 | — | — | 0.7% | Aug 9, 2017 | IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability a... |
| CVE-2016-5716 | — | — | 1.8% | Aug 9, 2017 | The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allow... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now