2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-0781The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0...
CVE-2016-0780HIGH7.5It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 a...
CVE-2016-0761CRITICAL9.8Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw i...
CVE-2016-9843CRITICAL9.8The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via v...
CVE-2016-9842HIGH8.8The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact v...
CVE-2016-9841CRITICAL9.8inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointe...
CVE-2016-9840HIGH8.8inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper point...
CVE-2016-7979Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently exec...
CVE-2016-7978Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors rela...
CVE-2016-7977Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read...
CVE-2016-5735Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have ...
CVE-2016-5178Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of s...
CVE-2016-5177Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of se...
CVE-2016-1876The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privil...
CVE-2016-10073The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai...
CVE-2016-6112IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate t...
CVE-2016-2172Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-7804Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges vi...
CVE-2016-4905SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allo...
CVE-2016-4904Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions pri...
CVE-2016-4903Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 a...
CVE-2016-4901Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain priv...
CVE-2016-4900Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privil...
CVE-2016-4863The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Cla...
CVE-2016-4854Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijac...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now