2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5867——In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can ...
CVE-2016-5864——In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some para...
CVE-2016-5863——In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity ch...
CVE-2016-5862——When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for M...
CVE-2016-5861——In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable contro...
CVE-2016-5860——In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is c...
CVE-2016-5859——In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is ca...
CVE-2016-5858——In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplie...
CVE-2016-5855——In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is...
CVE-2016-5854——In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be...
CVE-2016-5853——In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check e...
CVE-2016-5347——In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to users...
CVE-2016-6029——IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive inform...
CVE-2016-6021——IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerabilit...
CVE-2016-6796HIGH7.5A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to...
CVE-2016-8745——A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5...
CVE-2016-6817HIGH7.5The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header ...
CVE-2016-6797HIGH7.5The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0...
CVE-2016-8739——The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyRea...
CVE-2016-6812——The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to prov...
CVE-2016-6794MEDIUM5.3When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the ...
CVE-2016-5018CRITICAL9.1In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malici...
CVE-2016-0762MEDIUM5.9The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to ...
CVE-2016-8949——IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, ...
CVE-2016-6121——IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability a...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now