2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1000116 | — | — | 2.1% | Oct 21, 2016 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS |
| CVE-2016-1000115 | — | — | 2.9% | Oct 21, 2016 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS |
| CVE-2016-2848 | — | — | 25.8% | Oct 21, 2016 | ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (asserti... |
| CVE-2016-8660 | — | — | 0.3% | Oct 16, 2016 | The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure a... |
| CVE-2016-8658 | — | — | 0.6% | Oct 16, 2016 | Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/... |
| CVE-2016-7097 | — | — | 0.4% | Oct 16, 2016 | The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which a... |
| CVE-2016-7042 | — | — | 0.4% | Oct 16, 2016 | The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection ... |
| CVE-2016-6828 | — | — | 1.2% | Oct 16, 2016 | The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certai... |
| CVE-2016-6327 | — | — | 0.4% | Oct 16, 2016 | drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (... |
| CVE-2016-0249 | — | — | 1.5% | Oct 16, 2016 | SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p... |
| CVE-2016-0204 | — | — | 1.1% | Oct 16, 2016 | Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redire... |
| CVE-2016-7211 | — | — | 3.0% | Oct 14, 2016 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, ... |
| CVE-2016-7194 | — | — | 57.9% | Oct 14, 2016 | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se... |
| CVE-2016-7190 | — | — | 66.9% | Oct 14, 2016 | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se... |
| CVE-2016-7189 | — | — | 48.1% | Oct 14, 2016 | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site,... |
| CVE-2016-7188 | — | — | 3.7% | Oct 14, 2016 | The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar... |
| CVE-2016-7185 | — | — | 3.4% | Oct 14, 2016 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, ... |
| CVE-2016-7182 | — | — | 30.3% | Oct 14, 2016 | The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; W... |
| CVE-2016-3396 | — | — | 24.4% | Oct 14, 2016 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows ... |
| CVE-2016-3392 | — | — | 10.0% | Oct 14, 2016 | The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote att... |
| CVE-2016-3391 | — | — | 7.9% | Oct 14, 2016 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by le... |
| CVE-2016-3390 | — | — | 16.8% | Oct 14, 2016 | The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c... |
| CVE-2016-3389 | — | — | 15.2% | Oct 14, 2016 | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se... |
| CVE-2016-3388 | — | — | 27.6% | Oct 14, 2016 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al... |
| CVE-2016-3387 | — | — | 19.9% | Oct 14, 2016 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now