2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10345 | — | — | 0.5% | Apr 18, 2017 | In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which... |
| CVE-2016-3038 | — | — | 0.5% | Apr 17, 2017 | IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2016-3037 | — | — | 0.9% | Apr 17, 2017 | IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticat... |
| CVE-2016-3036 | — | — | 1.7% | Apr 17, 2017 | IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing ... |
| CVE-2016-0228 | — | — | 0.6% | Apr 17, 2017 | IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulner... |
| CVE-2016-5396 | — | — | 2.9% | Apr 17, 2017 | Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. |
| CVE-2016-7551 | — | — | 5.5% | Apr 17, 2017 | chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 an... |
| CVE-2016-6727 | — | — | 2.7% | Apr 17, 2017 | The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code. |
| CVE-2016-6726 | — | — | 0.8% | Apr 17, 2017 | Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices. |
| CVE-2016-4874 | — | — | 1.0% | Apr 17, 2017 | Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack. |
| CVE-2016-4873 | — | — | 1.2% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project fun... |
| CVE-2016-4872 | — | — | 1.4% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of u... |
| CVE-2016-4871 | — | — | 2.3% | Apr 17, 2017 | Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service. |
| CVE-2016-4870 | — | — | 1.0% | Apr 17, 2017 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbi... |
| CVE-2016-4869 | — | — | 2.0% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment vari... |
| CVE-2016-4868 | — | — | 1.5% | Apr 17, 2017 | Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email ... |
| CVE-2016-4867 | — | — | 1.4% | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized pr... |
| CVE-2016-4866 | — | — | 0.8% | Apr 17, 2017 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject... |
| CVE-2016-4865 | — | — | 0.8% | Apr 17, 2017 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject... |
| CVE-2016-8602 | — | — | 3.2% | Apr 14, 2017 | The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service... |
| CVE-2016-7060 | — | — | 0.4% | Apr 14, 2017 | The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physicall... |
| CVE-2016-7032 | — | — | 0.3% | Apr 14, 2017 | sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via... |
| CVE-2016-6299 | — | — | 1.7% | Apr 14, 2017 | The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privilege... |
| CVE-2016-5312 | — | — | 53.7% | Apr 14, 2017 | Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au... |
| CVE-2016-4890 | — | — | 3.5% | Apr 14, 2017 | ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now