2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8751——Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Adm...
CVE-2016-8746——Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wi...
CVE-2016-10342——In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
CVE-2016-10341——In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
CVE-2016-10340——In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability e...
CVE-2016-10339——In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystor...
CVE-2016-10338——In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
CVE-2016-10337——In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
CVE-2016-10336——In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
CVE-2016-10335——In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
CVE-2016-10334——In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr...
CVE-2016-10333——In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
CVE-2016-10332——In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
CVE-2016-9984——IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the...
CVE-2016-9973——IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...
CVE-2016-5391——libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon re...
CVE-2016-3704——Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
CVE-2016-5411——/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created wor...
CVE-2016-3696——The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
CVE-2016-8219MEDIUM6.5An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to ...
CVE-2016-8218——An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 20...
CVE-2016-6655——An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release ve...
CVE-2016-7838——Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary c...
CVE-2016-7837——Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used ...
CVE-2016-7836CRITICAL9.8SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now