2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8746Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wi...
CVE-2016-10342In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
CVE-2016-10341In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
CVE-2016-10340In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability e...
CVE-2016-10339In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystor...
CVE-2016-10338In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
CVE-2016-10337In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
CVE-2016-10336In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
CVE-2016-10335In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
CVE-2016-10334In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr...
CVE-2016-10333In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
CVE-2016-10332In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
CVE-2016-9984IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the...
CVE-2016-9973IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...
CVE-2016-5391libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon re...
CVE-2016-3704Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
CVE-2016-5411/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created wor...
CVE-2016-3696The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
CVE-2016-8219MEDIUM6.5An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to ...
CVE-2016-8218An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 20...
CVE-2016-6655An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release ve...
CVE-2016-7838Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary c...
CVE-2016-7837Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used ...
CVE-2016-7836CRITICAL9.8SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the...
CVE-2016-7835Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certific...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now