2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-6288——The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of se...
CVE-2016-5137——The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP)...
CVE-2016-5136——Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome...
CVE-2016-5135——WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not c...
CVE-2016-5134——net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure t...
CVE-2016-5133——Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-mid...
CVE-2016-5132——The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts speci...
CVE-2016-5130——content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of ...
CVE-2016-5129——Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed object...
CVE-2016-5128——objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API intercepto...
CVE-2016-5127——Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52...
CVE-2016-1711——WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame...
CVE-2016-1710——The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome b...
CVE-2016-1709——Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly before 2016-06-10, as use...
CVE-2016-1708——The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82...
CVE-2016-1707——ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid U...
CVE-2016-1706——The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin...
CVE-2016-1705——Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.82 allow attackers to cause a denial of service o...
CVE-2016-6204——Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2...
CVE-2016-5874——Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outag...
CVE-2016-5744——Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted ...
CVE-2016-5743——Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed...
CVE-2016-6224——ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using G...
CVE-2016-4653——The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local user...
CVE-2016-4652——CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and cons...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now