2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4471——ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
CVE-2016-4457——CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
CVE-2016-3690——The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serial...
CVE-2016-3112——client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as w...
CVE-2016-3111——pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the p...
CVE-2016-3108——The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary fil...
CVE-2016-3107——The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/...
CVE-2016-3091——Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
CVE-2016-2034——SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
CVE-2016-4973——Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow loc...
CVE-2016-9977——IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the fa...
CVE-2016-9710——IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote at...
CVE-2016-8939——IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows R...
CVE-2016-6089——IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they shoul...
CVE-2016-6087CRITICAL9.8IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data us...
CVE-2016-5960——IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be rea...
CVE-2016-5959——IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead t...
CVE-2016-3051——IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of t...
CVE-2016-3019——IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacke...
CVE-2016-0254——IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity In...
CVE-2016-9834——An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph...
CVE-2016-9961——game-music-emu before 0.6.1 mishandles unspecified integer values.
CVE-2016-9960——game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
CVE-2016-5004——The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a...
CVE-2016-3077——The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now