Skip to main content

Year archive

CVEs published in 2016

Archive summary

6,449 CVEs published in 2016 — 895 Critical, 2,887 High, 2,446 Medium, 221 Low, 0 Unrated.

CVE-2016-9564

Published Nov 30, 2016

Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5987

Published Nov 30, 2016

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive information via a crafted HTTP re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5905

Published Nov 30, 2016

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticated users to inject arbitrary we…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5890

Published Nov 30, 2016

IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote authenticated users to change arbitrary passwords via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3057

Published Nov 30, 2016

Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.2 before 5020500_14 and 5.2 06 before 5020602_1 allows remote attackers to inject arbitrary web script or…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3014

Published Nov 30, 2016

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 befor…

CVSS 5.4 · Medium

CVE-2016-3009

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authenticat…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-3004

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authenticat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3002

Published Nov 30, 2016

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client devic…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2963

Published Nov 30, 2016

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2958

Published Nov 30, 2016

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2957

Published Nov 30, 2016

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2953

Published Nov 30, 2016

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2952

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2951

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechani…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2950

Published Nov 30, 2016

SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2949

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2948

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2944

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2943

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2940

Published Nov 30, 2016

Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 6,449 CVEsPage 22 of 258