2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7802 | — | — | 2.5% | Jun 9, 2017 | Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrar... |
| CVE-2016-7801 | — | — | 1.1% | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via uns... |
| CVE-2016-4910 | — | — | 1.1% | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operatio... |
| CVE-2016-4909 | — | — | 1.3% | Jun 9, 2017 | Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the au... |
| CVE-2016-4908 | — | — | 1.1% | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete anoth... |
| CVE-2016-4907 | — | — | 0.8% | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors. |
| CVE-2016-4906 | — | — | 1.2% | Jun 9, 2017 | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web scrip... |
| CVE-2016-4902 | — | — | 1.8% | Jun 9, 2017 | Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for W... |
| CVE-2016-7469 | — | — | 0.9% | Jun 9, 2017 | A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AA... |
| CVE-2016-9991 | — | — | 0.6% | Jun 8, 2017 | IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker ... |
| CVE-2016-9736 | — | — | 2.3% | Jun 8, 2017 | IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive informa... |
| CVE-2016-9698 | — | — | 2.0% | Jun 8, 2017 | IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)... |
| CVE-2016-8987 | — | — | 1.0% | Jun 8, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they sh... |
| CVE-2016-6098 | — | — | 1.0% | Jun 8, 2017 | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way tha... |
| CVE-2016-6093 | — | — | 1.8% | Jun 8, 2017 | IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it eas... |
| CVE-2016-6594 | — | — | 1.2% | Jun 8, 2017 | Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requ... |
| CVE-2016-5648 | — | — | 1.2% | Jun 8, 2017 | Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers... |
| CVE-2016-4473 | — | — | 7.8% | Jun 8, 2017 | /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as p... |
| CVE-2016-7050 | — | — | 4.8% | Jun 8, 2017 | SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Ent... |
| CVE-2016-5416 | — | — | 2.9% | Jun 8, 2017 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red... |
| CVE-2016-5405 | — | — | 3.1% | Jun 8, 2017 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red... |
| CVE-2016-4992 | — | — | 2.4% | Jun 8, 2017 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red... |
| CVE-2016-3099 | — | — | 1.7% | Jun 8, 2017 | mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, an... |
| CVE-2016-3095 | — | — | 0.3% | Jun 8, 2017 | server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key. |
| CVE-2016-4471 | — | — | 2.3% | Jun 8, 2017 | ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now