2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7041 | MEDIUM | 6.5 | 4.0% | Sep 10, 2018 | Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to b... |
| CVE-2016-7078 | MEDIUM | 4.3 | 1.4% | Sep 10, 2018 | foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u... |
| CVE-2016-7077 | MEDIUM | 4.3 | 1.4% | Sep 10, 2018 | foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt... |
| CVE-2016-7067 | MEDIUM | 6.5 | 0.9% | Sep 10, 2018 | Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an... |
| CVE-2016-9040 | MEDIUM | 5.5 | 0.5% | Sep 7, 2018 | An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerab... |
| CVE-2016-0234 | MEDIUM | 4 | 0.3% | Aug 30, 2018 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous us... |
| CVE-2016-9605 | MEDIUM | 6.1 | 0.8% | Aug 22, 2018 | A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnera... |
| CVE-2016-9598 | MEDIUM | 6.5 | 1.0% | Aug 16, 2018 | libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of... |
| CVE-2016-9596 | MEDIUM | 6.5 | 0.9% | Aug 16, 2018 | libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a... |
| CVE-2016-9583 | MEDIUM | 5.5 | 1.9% | Aug 1, 2018 | An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when process... |
| CVE-2016-9579 | MEDIUM | 6.5 | 4.4% | Aug 1, 2018 | A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to a... |
| CVE-2016-9572 | MEDIUM | 5.9 | 2.2% | Aug 1, 2018 | A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error i... |
| CVE-2016-8653 | MEDIUM | 5.3 | 1.9% | Aug 1, 2018 | It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it... |
| CVE-2016-8641 | MEDIUM | 6.7 | 1.1% | Aug 1, 2018 | A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil... |
| CVE-2016-8608 | MEDIUM | 5.4 | 1.3% | Aug 1, 2018 | JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplet... |
| CVE-2016-8639 | MEDIUM | 6.1 | 1.2% | Aug 1, 2018 | It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could a... |
| CVE-2016-8637 | MEDIUM | 5 | 0.3% | Aug 1, 2018 | A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable... |
| CVE-2016-8635 | MEDIUM | 5.3 | 2.0% | Aug 1, 2018 | It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement... |
| CVE-2016-8634 | MEDIUM | 6.1 | 1.1% | Aug 1, 2018 | A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains ... |
| CVE-2016-9573 | MEDIUM | 6.5 | 2.6% | Aug 1, 2018 | An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafte... |
| CVE-2016-8625 | MEDIUM | 5.3 | 4.3% | Aug 1, 2018 | curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users... |
| CVE-2016-8620 | MEDIUM | 6.5 | 4.4% | Aug 1, 2018 | The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read vi... |
| CVE-2016-8619 | MEDIUM | 5.3 | 5.0% | Aug 1, 2018 | The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free. |
| CVE-2016-8615 | MEDIUM | 5.3 | 4.5% | Aug 1, 2018 | A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back ... |
| CVE-2016-8621 | MEDIUM | 5.3 | 4.9% | Jul 31, 2018 | The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now