2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1217 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1216 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1215 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1214 | — | — | 1.2% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. |
| CVE-2016-1213 | — | — | 1.3% | Apr 20, 2017 | The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. |
| CVE-2016-6347 | — | — | 1.6% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject ... |
| CVE-2016-6341 | — | — | 0.3% | Apr 20, 2017 | oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local ... |
| CVE-2016-6338 | — | — | 0.5% | Apr 20, 2017 | ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, all... |
| CVE-2016-6337 | — | — | 1.2% | Apr 20, 2017 | MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging... |
| CVE-2016-6336 | — | — | 1.0% | Apr 20, 2017 | MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete... |
| CVE-2016-6335 | — | — | 1.7% | Apr 20, 2017 | MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of ... |
| CVE-2016-6334 | — | — | 1.1% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x... |
| CVE-2016-6333 | — | — | 1.0% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x bef... |
| CVE-2016-6332 | — | — | 1.5% | Apr 20, 2017 | MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allo... |
| CVE-2016-6331 | — | — | 2.1% | Apr 20, 2017 | ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass i... |
| CVE-2016-5762 | — | — | 5.7% | Apr 20, 2017 | Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remo... |
| CVE-2016-5761 | — | — | 1.3% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote att... |
| CVE-2016-5760 | — | — | 1.3% | Apr 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Serv... |
| CVE-2016-5409 | — | — | 1.3% | Apr 20, 2017 | Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which ma... |
| CVE-2016-4849 | — | — | 1.3% | Apr 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbi... |
| CVE-2016-4847 | — | — | 1.3% | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject... |
| CVE-2016-4650 | — | — | 2.0% | Apr 20, 2017 | Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows a... |
| CVE-2016-4293 | — | — | 3.6% | Apr 20, 2017 | Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle function... |
| CVE-2016-1219 | — | — | 3.3% | Apr 20, 2017 | Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. |
| CVE-2016-5410 | — | — | 0.4% | Apr 19, 2017 | firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now