2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-8624 | MEDIUM | 5.3 | 5.9% | Jul 31, 2018 | curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with ... |
| CVE-2016-8618 | MEDIUM | 5.3 | 4.6% | Jul 31, 2018 | The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to a... |
| CVE-2016-8614 | MEDIUM | 6.3 | 2.5% | Jul 31, 2018 | A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing... |
| CVE-2016-8631 | MEDIUM | 6.3 | 1.1% | Jul 31, 2018 | The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with acc... |
| CVE-2016-8613 | MEDIUM | 6.4 | 2.4% | Jul 31, 2018 | A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. ... |
| CVE-2016-8611 | MEDIUM | 4.3 | 2.3% | Jul 31, 2018 | A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2... |
| CVE-2016-8626 | MEDIUM | 6.5 | 2.3% | Jul 31, 2018 | A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an au... |
| CVE-2016-9603 | MEDIUM | 5.5 | 4.4% | Jul 27, 2018 | A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; t... |
| CVE-2016-8647 | MEDIUM | 4.9 | 1.4% | Jul 26, 2018 | An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly c... |
| CVE-2016-9574 | MEDIUM | 5.9 | 1.4% | Jul 19, 2018 | nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicke... |
| CVE-2016-9604 | MEDIUM | 4.4 | 0.3% | Jul 11, 2018 | It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '... |
| CVE-2016-9042 | MEDIUM | 5.9 | 4.0% | Jun 4, 2018 | An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A spe... |
| CVE-2016-10597 | MEDIUM | 5.9 | 0.5% | Jun 1, 2018 | cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks. |
| CVE-2016-7076 | MEDIUM | 6.4 | 0.5% | May 29, 2018 | sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo execut... |
| CVE-2016-8627 | MEDIUM | 4.3 | 2.7% | May 11, 2018 | admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that all... |
| CVE-2016-9590 | MEDIUM | 6.5 | 1.2% | Apr 26, 2018 | puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform direc... |
| CVE-2016-9601 | MEDIUM | 5.3 | 1.8% | Apr 24, 2018 | ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_de... |
| CVE-2016-9594 | MEDIUM | 6.5 | 2.7% | Apr 23, 2018 | curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 3... |
| CVE-2016-9586 | MEDIUM | 5.9 | 5.0% | Apr 23, 2018 | curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's impl... |
| CVE-2016-9593 | MEDIUM | 4.7 | 1.0% | Apr 16, 2018 | foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the f... |
| CVE-2016-9592 | MEDIUM | 4.3 | 1.3% | Apr 16, 2018 | openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes th... |
| CVE-2016-9711 | MEDIUM | 5.3 | 1.7% | Mar 22, 2018 | IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages... |
| CVE-2016-10704 | MEDIUM | 6.1 | 0.6% | Dec 30, 2017 | Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that... |
| CVE-2016-1252 | MEDIUM | 5.9 | 7.2% | Dec 5, 2017 | The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1... |
| CVE-2016-6794 | MEDIUM | 5.3 | 7.2% | Aug 10, 2017 | When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now