2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-10703HIGH7.5A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, befo...
CVE-2016-6804HIGH7.8The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains...
CVE-2016-8610HIGH7.5A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL proto...
CVE-2016-5714HIGH7.2Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to by...
CVE-2016-4925HIGH7.5Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor excepti...
CVE-2016-4924HIGH8.4An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host ...
CVE-2016-4923HIGH8Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a rem...
CVE-2016-4922HIGH8.4Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow un...
CVE-2016-4921HIGH7.5By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can ...
CVE-2016-1261HIGH7.1J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-W...
CVE-2016-0732HIGH8.8The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 th...
CVE-2016-6796HIGH7.5A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to...
CVE-2016-6817HIGH7.5The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header ...
CVE-2016-6797HIGH7.5The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0...
CVE-2016-4456HIGH7.5The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary...
CVE-2016-6220HIGH7.5Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.
CVE-2016-8743HIGH7.5Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and...
CVE-2016-10402HIGH7.8Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header...
CVE-2016-6342HIGH7.5elog 3.1.1 allows remote attackers to post data as any username in the logbook.
CVE-2016-0780HIGH7.5It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 a...
CVE-2016-9842HIGH8.8The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact v...
CVE-2016-9840HIGH8.8inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper point...
CVE-2016-8741HIGH7.5The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user auth...
CVE-2016-4879HIGH8.8Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attacke...
CVE-2016-4838HIGH7.8The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now