2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-8746 | — | — | 2.7% | Jun 14, 2017 | Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wi... |
| CVE-2016-10342 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler. |
| CVE-2016-10341 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended. |
| CVE-2016-10340 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability e... |
| CVE-2016-10339 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystor... |
| CVE-2016-10338 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing. |
| CVE-2016-10337 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed. |
| CVE-2016-10336 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot. |
| CVE-2016-10335 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. |
| CVE-2016-10334 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr... |
| CVE-2016-10333 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. |
| CVE-2016-10332 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications. |
| CVE-2016-9984 | — | — | 1.6% | Jun 13, 2017 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the... |
| CVE-2016-9973 | — | — | 0.7% | Jun 13, 2017 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2016-5391 | — | — | 3.0% | Jun 13, 2017 | libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon re... |
| CVE-2016-3704 | — | — | 1.9% | Jun 13, 2017 | Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords. |
| CVE-2016-5411 | — | — | 2.3% | Jun 13, 2017 | /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created wor... |
| CVE-2016-3696 | — | — | 0.4% | Jun 13, 2017 | The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key. |
| CVE-2016-8219 | MEDIUM | 6.5 | 1.0% | Jun 13, 2017 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to ... |
| CVE-2016-8218 | — | — | 1.3% | Jun 13, 2017 | An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 20... |
| CVE-2016-6655 | — | — | 3.4% | Jun 13, 2017 | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release ve... |
| CVE-2016-7838 | — | — | 2.6% | Jun 9, 2017 | Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary c... |
| CVE-2016-7837 | — | — | 0.6% | Jun 9, 2017 | Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used ... |
| CVE-2016-7836 | CRITICAL | 9.8 | 19.4% | Jun 9, 2017 | SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the... |
| CVE-2016-7835 | — | — | 2.2% | Jun 9, 2017 | Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certific... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now