2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4457 | — | — | 1.1% | Jun 8, 2017 | CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate. |
| CVE-2016-3690 | — | — | 5.2% | Jun 8, 2017 | The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serial... |
| CVE-2016-3112 | — | — | 2.2% | Jun 8, 2017 | client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as w... |
| CVE-2016-3111 | — | — | 0.4% | Jun 8, 2017 | pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the p... |
| CVE-2016-3108 | — | — | 0.3% | Jun 8, 2017 | The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary fil... |
| CVE-2016-3107 | — | — | 0.2% | Jun 8, 2017 | The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/... |
| CVE-2016-3091 | — | — | 1.2% | Jun 8, 2017 | Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service. |
| CVE-2016-2034 | — | — | 1.0% | Jun 8, 2017 | SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0. |
| CVE-2016-4973 | — | — | 0.4% | Jun 7, 2017 | Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow loc... |
| CVE-2016-9977 | — | — | 1.8% | Jun 7, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the fa... |
| CVE-2016-9710 | — | — | 1.6% | Jun 7, 2017 | IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote at... |
| CVE-2016-8939 | — | — | 0.4% | Jun 7, 2017 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows R... |
| CVE-2016-6089 | — | — | 0.3% | Jun 7, 2017 | IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they shoul... |
| CVE-2016-6087 | CRITICAL | 9.8 | 1.9% | Jun 7, 2017 | IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data us... |
| CVE-2016-5960 | — | — | 0.3% | Jun 7, 2017 | IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be rea... |
| CVE-2016-5959 | — | — | 1.3% | Jun 7, 2017 | IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead t... |
| CVE-2016-3051 | — | — | 0.9% | Jun 7, 2017 | IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of t... |
| CVE-2016-3019 | — | — | 0.8% | Jun 7, 2017 | IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacke... |
| CVE-2016-0254 | — | — | 1.9% | Jun 7, 2017 | IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity In... |
| CVE-2016-9834 | — | — | 1.8% | Jun 7, 2017 | An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph... |
| CVE-2016-9961 | — | — | 4.4% | Jun 6, 2017 | game-music-emu before 0.6.1 mishandles unspecified integer values. |
| CVE-2016-9960 | — | — | 0.5% | Jun 6, 2017 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). |
| CVE-2016-5004 | — | — | 6.4% | Jun 6, 2017 | The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a... |
| CVE-2016-3077 | — | — | 1.0% | Jun 6, 2017 | The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of ... |
| CVE-2016-3066 | — | — | 1.0% | Jun 6, 2017 | The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now