2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2165MEDIUM6.5The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5...
CVE-2016-0781——The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0...
CVE-2016-0780HIGH7.5It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 a...
CVE-2016-0761CRITICAL9.8Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw i...
CVE-2016-9843CRITICAL9.8The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via v...
CVE-2016-9842HIGH8.8The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact v...
CVE-2016-9841CRITICAL9.8inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointe...
CVE-2016-9840HIGH8.8inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper point...
CVE-2016-7979——Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently exec...
CVE-2016-7978——Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors rela...
CVE-2016-7977——Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read...
CVE-2016-5735——Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have ...
CVE-2016-5178——Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of s...
CVE-2016-5177——Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of se...
CVE-2016-1876——The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privil...
CVE-2016-10073——The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai...
CVE-2016-6112——IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate t...
CVE-2016-2172——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-7804——Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges vi...
CVE-2016-4905——SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allo...
CVE-2016-4904——Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions pri...
CVE-2016-4903——Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 a...
CVE-2016-4901——Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain priv...
CVE-2016-4900——Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privil...
CVE-2016-4863——The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Cla...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now