2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4374 | — | — | 1.8% | Aug 8, 2016 | HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-si... |
| CVE-2016-1478 | — | — | 1.9% | Aug 8, 2016 | Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows rem... |
| CVE-2016-1474 | — | — | 1.3% | Aug 8, 2016 | Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote at... |
| CVE-2016-1468 | — | — | 2.9% | Aug 8, 2016 | The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authen... |
| CVE-2016-1466 | — | — | 2.9% | Aug 8, 2016 | Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) S... |
| CVE-2016-1430 | — | — | 3.7% | Aug 8, 2016 | Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP... |
| CVE-2016-1429 | — | — | 7.4% | Aug 8, 2016 | Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read... |
| CVE-2016-6515 | — | — | 57.7% | Aug 7, 2016 | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a... |
| CVE-2016-5146 | — | — | 1.4% | Aug 7, 2016 | Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service ... |
| CVE-2016-5145 | — | — | 1.4% | Aug 7, 2016 | Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structu... |
| CVE-2016-5144 | — | — | 1.7% | Aug 7, 2016 | The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the scr... |
| CVE-2016-5143 | — | — | 1.8% | Aug 7, 2016 | The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the scr... |
| CVE-2016-5142 | — | — | 1.7% | Aug 7, 2016 | The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does no... |
| CVE-2016-5141 | — | — | 1.5% | Aug 7, 2016 | Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors invol... |
| CVE-2016-5140 | — | — | 1.9% | Aug 7, 2016 | Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chro... |
| CVE-2016-5139 | — | — | 1.3% | Aug 7, 2016 | Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome be... |
| CVE-2016-1951 | — | — | 2.7% | Aug 7, 2016 | Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers ... |
| CVE-2016-6635 | — | — | 2.5% | Aug 7, 2016 | Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-ac... |
| CVE-2016-6634 | — | — | 2.5% | Aug 7, 2016 | Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to... |
| CVE-2016-5359 | — | — | 2.6% | Aug 7, 2016 | epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allow... |
| CVE-2016-5358 | — | — | 2.3% | Aug 7, 2016 | epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data... |
| CVE-2016-5357 | — | — | 2.5% | Aug 7, 2016 | wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles ssca... |
| CVE-2016-5356 | — | — | 2.5% | Aug 7, 2016 | wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf uns... |
| CVE-2016-5355 | — | — | 2.5% | Aug 7, 2016 | wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf u... |
| CVE-2016-5354 | — | — | 2.8% | Aug 7, 2016 | The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote at... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now