2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4456 | HIGH | 7.5 | 2.2% | Aug 8, 2017 | The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary... |
| CVE-2016-7976 | — | — | 23.5% | Aug 7, 2017 | The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams... |
| CVE-2016-6220 | HIGH | 7.5 | 4.9% | Aug 7, 2017 | Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0. |
| CVE-2016-3113 | MEDIUM | 6.1 | 2.7% | Aug 7, 2017 | Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML. |
| CVE-2016-10404 | — | — | 0.7% | Aug 7, 2017 | XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/front... |
| CVE-2016-9981 | — | — | 1.4% | Aug 2, 2017 | IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid ... |
| CVE-2016-7845 | — | — | 1.4% | Aug 2, 2017 | GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may b... |
| CVE-2016-7844 | — | — | 0.9% | Aug 2, 2017 | GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail te... |
| CVE-2016-7812 | — | — | 0.8% | Aug 2, 2017 | The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker... |
| CVE-2016-9719 | — | — | 1.2% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hij... |
| CVE-2016-9718 | — | — | 0.7% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scriptin... |
| CVE-2016-9717 | — | — | 1.1% | Jul 31, 2017 | HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, a... |
| CVE-2016-9716 | — | — | 0.7% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forger... |
| CVE-2016-9715 | — | — | 0.7% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. Thi... |
| CVE-2016-9714 | — | — | 0.6% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request ... |
| CVE-2016-8743 | HIGH | 7.5 | 13.3% | Jul 27, 2017 | Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and... |
| CVE-2016-2161 | — | — | 21.0% | Jul 27, 2017 | In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and ea... |
| CVE-2016-0736 | — | — | 49.0% | Jul 27, 2017 | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured c... |
| CVE-2016-10399 | — | — | 1.4% | Jul 27, 2017 | Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remo... |
| CVE-2016-10402 | HIGH | 7.8 | 10.2% | Jul 27, 2017 | Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header... |
| CVE-2016-6133 | — | — | 0.8% | Jul 25, 2017 | Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows... |
| CVE-2016-10401 | — | — | 12.3% | Jul 25, 2017 | ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access... |
| CVE-2016-7539 | — | — | 4.9% | Jul 25, 2017 | Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory... |
| CVE-2016-8975 | — | — | 0.7% | Jul 24, 2017 | IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2016-6118 | — | — | 0.7% | Jul 24, 2017 | IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows use... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now