2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5864In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some para...
CVE-2016-5863In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity ch...
CVE-2016-5862When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for M...
CVE-2016-5861In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable contro...
CVE-2016-5860In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is c...
CVE-2016-5859In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is ca...
CVE-2016-5858In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplie...
CVE-2016-5855In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is...
CVE-2016-5854In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be...
CVE-2016-5853In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check e...
CVE-2016-5347In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to users...
CVE-2016-6029IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive inform...
CVE-2016-6021IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerabilit...
CVE-2016-6796HIGH7.5A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to...
CVE-2016-8745A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5...
CVE-2016-6817HIGH7.5The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header ...
CVE-2016-6797HIGH7.5The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0...
CVE-2016-8739The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyRea...
CVE-2016-6812The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to prov...
CVE-2016-6794MEDIUM5.3When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the ...
CVE-2016-5018CRITICAL9.1In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malici...
CVE-2016-0762MEDIUM5.9The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to ...
CVE-2016-8949IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, ...
CVE-2016-6121IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability a...
CVE-2016-5716The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allow...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now