2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-3113MEDIUM6.1Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
CVE-2016-5394MEDIUM6.1In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() meth...
CVE-2016-0764MEDIUM6.2Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Li...
CVE-2016-8219MEDIUM6.5An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to ...
CVE-2016-2192MEDIUM6.5PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
CVE-2016-0767MEDIUM6.5PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter th...
CVE-2016-2165MEDIUM6.5The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5...
CVE-2016-10374MEDIUM5.5perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current workin...
CVE-2016-4877MEDIUM5.4Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attack...
CVE-2016-4839MEDIUM5.5The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for...
CVE-2016-2126MEDIUM6.5Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Att...
CVE-2016-7055MEDIUM5.9There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1....
CVE-2016-4840MEDIUM5.9Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL ce...
CVE-2016-4830MEDIUM5.9Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
CVE-2016-1184MEDIUM5.9Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.
CVE-2016-4075MEDIUM6.1Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related...
CVE-2016-7538MEDIUM6.5coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted fil...
CVE-2016-7536MEDIUM6.5magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted ...
CVE-2016-7535MEDIUM6.5coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted PSD...
CVE-2016-7534MEDIUM6.5The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a cra...
CVE-2016-7532MEDIUM6.5coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD ...
CVE-2016-7530MEDIUM6.5The quantum handling code in ImageMagick allows remote attackers to cause a denial of service (divide-by-zero error or o...
CVE-2016-7527MEDIUM6.5coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file...
CVE-2016-7526MEDIUM6.5coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted fil...
CVE-2016-7525MEDIUM6.5Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-b...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now