2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1429——Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read...
CVE-2016-6515——The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a...
CVE-2016-5340HIGH7.8The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android p...
CVE-2016-2065HIGH7.8sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualc...
CVE-2016-2064HIGH7.8sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualc...
CVE-2016-2063HIGH7.8Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal...
CVE-2016-5146——Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service ...
CVE-2016-5145——Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structu...
CVE-2016-5144——The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the scr...
CVE-2016-5143——The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the scr...
CVE-2016-5142——The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does no...
CVE-2016-5141——Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors invol...
CVE-2016-5140——Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chro...
CVE-2016-5139——Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome be...
CVE-2016-1951——Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers ...
CVE-2016-6635——Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-ac...
CVE-2016-6634——Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to...
CVE-2016-5359——epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allow...
CVE-2016-5358——epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data...
CVE-2016-5357——wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles ssca...
CVE-2016-5356——wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf uns...
CVE-2016-5355——wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf u...
CVE-2016-5354——The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote at...
CVE-2016-5353——epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishan...
CVE-2016-5352——epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now