2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-2120HIGH7.5An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authoriz...
CVE-2016-6328HIGH8.1A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can ...
CVE-2016-5402HIGH8.8A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, auth...
CVE-2016-9045HIGH8.8A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request...
CVE-2016-7070HIGH8A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it in...
CVE-2016-9048HIGH7.4Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially c...
CVE-2016-7035HIGH8.8An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attack...
CVE-2016-7071HIGH8.8It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passe...
CVE-2016-7075HIGH7.5It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate cert...
CVE-2016-9044HIGH8.8An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 ...
CVE-2016-7048HIGH8.1The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote at...
CVE-2016-8654HIGH7.8A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small...
CVE-2016-8648HIGH7.2It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects p...
CVE-2016-8628HIGH7.6Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker wit...
CVE-2016-9578HIGH7.5A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to...
CVE-2016-9577HIGH7.5A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker coul...
CVE-2016-9595HIGH7.3A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A loca...
CVE-2016-9487HIGH7.8EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation....
CVE-2016-6578HIGH8.8CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability...
CVE-2016-9079HIGH7.5A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis...
CVE-2016-8390HIGH7.8An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.1...
CVE-2016-10690HIGH8.1openframe-ascii-image module is an openframe plugin which adds support for ascii images via fim. openframe-ascii-image d...
CVE-2016-10688HIGH8.1Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP,...
CVE-2016-10663HIGH8.1wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, whic...
CVE-2016-1000338HIGH7.5In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on ve...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now