2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-8624MEDIUM5.3curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with ...
CVE-2016-8618MEDIUM5.3The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to a...
CVE-2016-8614MEDIUM6.3A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing...
CVE-2016-8631MEDIUM6.3The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with acc...
CVE-2016-8613MEDIUM6.4A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. ...
CVE-2016-8611MEDIUM4.3A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2...
CVE-2016-8626MEDIUM6.5A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an au...
CVE-2016-9603MEDIUM5.5A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; t...
CVE-2016-8647MEDIUM4.9An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly c...
CVE-2016-9574MEDIUM5.9nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicke...
CVE-2016-9604MEDIUM4.4It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '...
CVE-2016-9042MEDIUM5.9An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A spe...
CVE-2016-10597MEDIUM5.9cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
CVE-2016-7076MEDIUM6.4sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo execut...
CVE-2016-8627MEDIUM4.3admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that all...
CVE-2016-9590MEDIUM6.5puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform direc...
CVE-2016-9601MEDIUM5.3ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_de...
CVE-2016-9594MEDIUM6.5curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 3...
CVE-2016-9586MEDIUM5.9curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's impl...
CVE-2016-9593MEDIUM4.7foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the f...
CVE-2016-9592MEDIUM4.3openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes th...
CVE-2016-9711MEDIUM5.3IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages...
CVE-2016-10704MEDIUM6.1Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that...
CVE-2016-1252MEDIUM5.9The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1...
CVE-2016-6794MEDIUM5.3When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now