2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2192 | MEDIUM | 6.5 | 0.9% | Jun 6, 2017 | PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own. |
| CVE-2016-0768 | — | — | 1.4% | Jun 6, 2017 | PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. |
| CVE-2016-0767 | MEDIUM | 6.5 | 0.9% | Jun 6, 2017 | PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter th... |
| CVE-2016-0726 | — | — | 2.3% | Jun 6, 2017 | The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which ... |
| CVE-2016-10297 | — | — | 0.3% | Jun 6, 2017 | In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnera... |
| CVE-2016-8231 | — | — | 0.5% | Jun 4, 2017 | In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certifica... |
| CVE-2016-8230 | — | — | 1.1% | Jun 4, 2017 | In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, mach... |
| CVE-2016-8229 | — | — | 0.5% | Jun 4, 2017 | A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker w... |
| CVE-2016-8228 | — | — | 0.4% | Jun 4, 2017 | In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrati... |
| CVE-2016-3073 | — | — | — | Jun 1, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3079. Reason: This candidate is a reservation ... |
| CVE-2016-10373 | — | — | — | May 31, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10214. Reason: This candidate is a reservation... |
| CVE-2016-3083 | — | — | 1.0% | May 30, 2017 | Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). W... |
| CVE-2016-10379 | — | — | 1.7% | May 29, 2017 | The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators v... |
| CVE-2016-10378 | — | — | 1.3% | May 29, 2017 | e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.ph... |
| CVE-2016-10377 | — | — | 0.9% | May 29, 2017 | In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to... |
| CVE-2016-10376 | — | — | 1.2% | May 28, 2017 | Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused... |
| CVE-2016-8497 | — | — | — | May 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2016-8496 | — | — | — | May 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2016-10375 | — | — | 2.2% | May 26, 2017 | Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c. |
| CVE-2016-6256 | — | — | 7.9% | May 26, 2017 | SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML ... |
| CVE-2016-5007 | — | — | 2.8% | May 25, 2017 | Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mapping... |
| CVE-2016-4977 | — | — | 79.2% | May 25, 2017 | When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1... |
| CVE-2016-4435 | — | — | 0.9% | May 25, 2017 | An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow un... |
| CVE-2016-3084 | — | — | 1.2% | May 25, 2017 | The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions,... |
| CVE-2016-2165 | MEDIUM | 6.5 | 0.9% | May 25, 2017 | The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now