2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-7041MEDIUM6.5Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to b...
CVE-2016-7078MEDIUM4.3foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u...
CVE-2016-7077MEDIUM4.3foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt...
CVE-2016-7067MEDIUM6.5Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an...
CVE-2016-9040MEDIUM5.5An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerab...
CVE-2016-0234MEDIUM4IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous us...
CVE-2016-9605MEDIUM6.1A flaw was found in cobbler software component version 2.6.11-1. It suffers from an invalid parameter validation vulnera...
CVE-2016-9598MEDIUM6.5libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of...
CVE-2016-9596MEDIUM6.5libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a...
CVE-2016-9583MEDIUM5.5An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when process...
CVE-2016-9579MEDIUM6.5A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to a...
CVE-2016-9572MEDIUM5.9A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error i...
CVE-2016-8653MEDIUM5.3It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it...
CVE-2016-8641MEDIUM6.7A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil...
CVE-2016-8608MEDIUM5.4JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplet...
CVE-2016-8639MEDIUM6.1It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could a...
CVE-2016-8637MEDIUM5A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable...
CVE-2016-8635MEDIUM5.3It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement...
CVE-2016-8634MEDIUM6.1A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains ...
CVE-2016-9573MEDIUM6.5An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafte...
CVE-2016-8625MEDIUM5.3curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users...
CVE-2016-8620MEDIUM6.5The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read vi...
CVE-2016-8619MEDIUM5.3The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
CVE-2016-8615MEDIUM5.3A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back ...
CVE-2016-8621MEDIUM5.3The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now