2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4694——The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefo...
CVE-2016-4658——xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS befor...
CVE-2016-4618——Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote atta...
CVE-2016-4611——WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or...
CVE-2016-6532——DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrati...
CVE-2016-6531CRITICAL9.8Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative...
CVE-2016-5793——Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges...
CVE-2016-4845——Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, ...
CVE-2016-0918——EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governa...
CVE-2016-6413——The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binar...
CVE-2016-6412——The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is e...
CVE-2016-6411——Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certi...
CVE-2016-6410——The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is e...
CVE-2016-6409——The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote ...
CVE-2016-6408——Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity...
CVE-2016-6414——iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitr...
CVE-2016-6406——Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on E...
CVE-2016-6374CRITICAL9.8Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup c...
CVE-2016-6373——The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute ...
CVE-2016-5284——Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates fo...
CVE-2016-5283——Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier i...
CVE-2016-5282——Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attacker...
CVE-2016-5281——Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and...
CVE-2016-5280——Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firef...
CVE-2016-5279——Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now