2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7843 | — | — | 3.4% | Apr 28, 2017 | Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and Atta... |
| CVE-2016-7842 | — | — | 2.6% | Apr 28, 2017 | Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to ... |
| CVE-2016-7841 | — | — | 0.9% | Apr 28, 2017 | Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via ... |
| CVE-2016-7840 | — | — | 0.9% | Apr 28, 2017 | Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web script or HTML via th... |
| CVE-2016-7839 | — | — | 0.9% | Apr 28, 2017 | Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web script or HTML via the ... |
| CVE-2016-7815 | — | — | 0.4% | Apr 28, 2017 | Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain acce... |
| CVE-2016-8962 | — | — | 1.3% | Apr 26, 2017 | IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for ... |
| CVE-2016-8924 | — | — | 0.8% | Apr 26, 2017 | IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the fai... |
| CVE-2016-5483 | — | — | — | Apr 25, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-3600. Reason: This candidate is a reservation ... |
| CVE-2016-8030 | — | — | 1.2% | Apr 25, 2017 | A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch 8 and earlier allows... |
| CVE-2016-6915 | — | — | 0.4% | Apr 24, 2017 | Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Tab... |
| CVE-2016-6917 | — | — | 0.4% | Apr 24, 2017 | Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OT... |
| CVE-2016-6916 | — | — | 0.4% | Apr 24, 2017 | Integer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before O... |
| CVE-2016-6903 | — | — | 4.9% | Apr 24, 2017 | lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. |
| CVE-2016-6902 | — | — | 5.1% | Apr 24, 2017 | lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. |
| CVE-2016-5551 | — | — | 0.4% | Apr 24, 2017 | Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition).... |
| CVE-2016-5016 | — | — | 1.0% | Apr 24, 2017 | Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 1... |
| CVE-2016-4313 | — | — | 8.7% | Apr 24, 2017 | Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra... |
| CVE-2016-3691 | — | — | 0.6% | Apr 24, 2017 | Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request met... |
| CVE-2016-3114 | — | — | 0.9% | Apr 24, 2017 | Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leve... |
| CVE-2016-3076 | — | — | 2.6% | Apr 24, 2017 | Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cau... |
| CVE-2016-2564 | — | — | 1.3% | Apr 23, 2017 | Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid func... |
| CVE-2016-9954 | — | — | 2.4% | Apr 21, 2017 | The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote ... |
| CVE-2016-5168 | — | — | 1.7% | Apr 21, 2017 | Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain ... |
| CVE-2016-3702 | — | — | 1.2% | Apr 21, 2017 | Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext i... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now