2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2192MEDIUM6.5PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
CVE-2016-0768PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
CVE-2016-0767MEDIUM6.5PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter th...
CVE-2016-0726The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which ...
CVE-2016-10297In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnera...
CVE-2016-8231In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certifica...
CVE-2016-8230In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, mach...
CVE-2016-8229A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker w...
CVE-2016-8228In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrati...
CVE-2016-3073Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3079. Reason: This candidate is a reservation ...
CVE-2016-10373Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10214. Reason: This candidate is a reservation...
CVE-2016-3083Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). W...
CVE-2016-10379The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators v...
CVE-2016-10378e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.ph...
CVE-2016-10377In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to...
CVE-2016-10376Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused...
CVE-2016-8497Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2016-8496Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2016-10375Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.
CVE-2016-6256SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML ...
CVE-2016-5007Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mapping...
CVE-2016-4977When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1...
CVE-2016-4435An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow un...
CVE-2016-3084The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions,...
CVE-2016-2165MEDIUM6.5The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now