2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3292 | — | — | 7.1% | Sep 14, 2016 | Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to ... |
| CVE-2016-3291 | — | — | 13.0% | Sep 14, 2016 | Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obta... |
| CVE-2016-3247 | — | — | 71.5% | Sep 14, 2016 | Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of ... |
| CVE-2016-0141 | — | — | 4.9% | Sep 14, 2016 | The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private ke... |
| CVE-2016-0138 | — | — | 13.5% | Sep 14, 2016 | Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumul... |
| CVE-2016-0137 | — | — | 6.8% | Sep 14, 2016 | The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protec... |
| CVE-2016-6399 | — | — | 1.9% | Sep 12, 2016 | Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through ... |
| CVE-2016-6398 | — | — | 1.3% | Sep 12, 2016 | The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obta... |
| CVE-2016-6396 | — | — | 1.2% | Sep 12, 2016 | Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking opt... |
| CVE-2016-6395 | — | — | 1.1% | Sep 12, 2016 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center befo... |
| CVE-2016-6394 | — | — | 1.4% | Sep 12, 2016 | Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 al... |
| CVE-2016-6371 | — | — | 4.8% | Sep 12, 2016 | Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(... |
| CVE-2016-6370 | — | — | 2.4% | Sep 12, 2016 | Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(... |
| CVE-2016-5954 | — | — | 1.3% | Sep 12, 2016 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8... |
| CVE-2016-5927 | — | — | 0.3% | Sep 12, 2016 | IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x ... |
| CVE-2016-4852 | — | — | 1.7% | Sep 12, 2016 | YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing f... |
| CVE-2016-0331 | — | — | 0.8% | Sep 12, 2016 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Co... |
| CVE-2016-7134 | — | — | 4.8% | Sep 12, 2016 | ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attac... |
| CVE-2016-7133 | — | — | 4.1% | Sep 12, 2016 | Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allo... |
| CVE-2016-7132 | HIGH | 7.5 | 8.8% | Sep 12, 2016 | ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2016-7131 | HIGH | 7.5 | 8.8% | Sep 12, 2016 | ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2016-7130 | — | — | 6.7% | Sep 12, 2016 | The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers ... |
| CVE-2016-7129 | — | — | 6.8% | Sep 12, 2016 | The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers... |
| CVE-2016-7128 | — | — | 7.8% | Sep 12, 2016 | The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case ... |
| CVE-2016-7127 | — | — | 6.8% | Sep 12, 2016 | The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamm... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now