2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1674 | — | — | 1.6% | Jun 5, 2016 | The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy v... |
| CVE-2016-1673 | — | — | 1.6% | Jun 5, 2016 | Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspec... |
| CVE-2016-1672 | — | — | 1.5% | Jun 5, 2016 | The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google... |
| CVE-2016-1230 | — | — | 1.0% | Jun 5, 2016 | Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote a... |
| CVE-2016-1229 | — | — | 1.1% | Jun 5, 2016 | Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1 through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allow... |
| CVE-2016-1212 | — | — | 2.3% | Jun 5, 2016 | Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authen... |
| CVE-2016-4812 | — | — | 1.5% | Jun 4, 2016 | Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remot... |
| CVE-2016-4564 | — | — | 3.4% | Jun 4, 2016 | The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect func... |
| CVE-2016-4563 | — | — | 2.6% | Jun 4, 2016 | The TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles the... |
| CVE-2016-4562 | — | — | 2.6% | Jun 4, 2016 | The DrawDashPolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles calcul... |
| CVE-2016-1403 | — | — | 0.5% | Jun 4, 2016 | CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via ... |
| CVE-2016-1211 | — | — | 1.4% | Jun 4, 2016 | Cross-site scripting (XSS) vulnerability in Epoch Web Mailing List 0.31 and earlier allows remote attackers to inject ar... |
| CVE-2016-1390 | — | — | 0.4% | Jun 4, 2016 | Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Netw... |
| CVE-2016-0908 | — | — | 0.4% | Jun 4, 2016 | EMC Isilon OneFS 7.1.x before 7.1.1.9 and 7.2.x before 7.2.1.2 allows local users to obtain root shell access by leverag... |
| CVE-2016-4804 | — | — | 0.5% | Jun 3, 2016 | The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a cr... |
| CVE-2016-3944 | — | — | 2.0% | Jun 3, 2016 | UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing a... |
| CVE-2016-3096 | — | — | 0.5% | Jun 3, 2016 | The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local use... |
| CVE-2016-0376 | — | — | 5.7% | Jun 3, 2016 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1... |
| CVE-2016-0363 | — | — | 4.0% | Jun 3, 2016 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 bef... |
| CVE-2016-1388 | — | — | 1.7% | Jun 3, 2016 | Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Netw... |
| CVE-2016-1370 | — | — | 2.1% | Jun 3, 2016 | Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attack... |
| CVE-2016-4945 | — | — | 1.4% | Jun 1, 2016 | Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Bu... |
| CVE-2016-4810 | — | — | 0.9% | Jun 1, 2016 | Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 an... |
| CVE-2016-4423 | — | — | 1.9% | Jun 1, 2016 | The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in... |
| CVE-2016-1902 | — | — | 1.9% | Jun 1, 2016 | The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 d... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now