2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1864 | — | — | 1.9% | Jun 19, 2016 | The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in ... |
| CVE-2016-1862 | — | — | 0.6% | Jun 19, 2016 | Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information... |
| CVE-2016-1861 | — | — | 4.4% | Jun 19, 2016 | The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privi... |
| CVE-2016-1860 | — | — | 0.6% | Jun 19, 2016 | Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information... |
| CVE-2016-1196 | — | — | 1.0% | Jun 19, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obta... |
| CVE-2016-1192 | — | — | 1.5% | Jun 19, 2016 | Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authentic... |
| CVE-2016-1191 | — | — | 1.9% | Jun 19, 2016 | Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attacker... |
| CVE-2016-0912 | — | — | 3.5% | Jun 19, 2016 | EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change r... |
| CVE-2016-0911 | — | — | 1.0% | Jun 19, 2016 | EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 has a default no_root_squash option for NFS exports, which makes it ea... |
| CVE-2016-0392 | — | — | 0.5% | Jun 19, 2016 | IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x thro... |
| CVE-2016-1226 | — | — | 1.6% | Jun 19, 2016 | Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arb... |
| CVE-2016-1225 | — | — | 3.5% | Jun 19, 2016 | Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors. |
| CVE-2016-1197 | — | — | 1.0% | Jun 19, 2016 | Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary w... |
| CVE-2016-1195 | — | — | 1.8% | Jun 19, 2016 | Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbit... |
| CVE-2016-4821 | — | — | 1.6% | Jun 19, 2016 | I-O DATA DEVICE ETX-R devices allow remote attackers to cause a denial of service (web-server crash) via unspecified vec... |
| CVE-2016-4820 | — | — | 0.6% | Jun 19, 2016 | Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the a... |
| CVE-2016-4819 | — | — | 3.8% | Jun 19, 2016 | The printfDx function in Takumi Yamada DX Library for Borland C++ 3.13f through 3.16b, DX Library for Gnu C++ 3.13f thro... |
| CVE-2016-4817 | — | — | 4.4% | Jun 19, 2016 | lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remo... |
| CVE-2016-4816 | — | — | 1.4% | Jun 19, 2016 | BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover cr... |
| CVE-2016-4815 | — | — | 2.2% | Jun 19, 2016 | Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices ... |
| CVE-2016-4814 | — | — | 2.2% | Jun 19, 2016 | Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps b... |
| CVE-2016-4813 | — | — | 1.9% | Jun 19, 2016 | NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating ... |
| CVE-2016-4371 | — | — | 0.6% | Jun 19, 2016 | HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obt... |
| CVE-2016-1424 | — | — | 0.6% | Jun 19, 2016 | Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted ... |
| CVE-2016-1397 | — | — | 1.8% | Jun 19, 2016 | Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devic... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now