2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6515 | — | — | 57.7% | Aug 7, 2016 | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a... |
| CVE-2016-5340 | HIGH | 7.8 | 0.3% | Aug 7, 2016 | The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android p... |
| CVE-2016-2065 | HIGH | 7.8 | 1.4% | Aug 7, 2016 | sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualc... |
| CVE-2016-2064 | HIGH | 7.8 | 0.6% | Aug 7, 2016 | sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualc... |
| CVE-2016-2063 | HIGH | 7.8 | 0.5% | Aug 7, 2016 | Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal... |
| CVE-2016-5146 | — | — | 1.4% | Aug 7, 2016 | Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service ... |
| CVE-2016-5145 | — | — | 1.4% | Aug 7, 2016 | Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structu... |
| CVE-2016-5144 | — | — | 1.7% | Aug 7, 2016 | The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the scr... |
| CVE-2016-5143 | — | — | 1.8% | Aug 7, 2016 | The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the scr... |
| CVE-2016-5142 | — | — | 1.7% | Aug 7, 2016 | The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does no... |
| CVE-2016-5141 | — | — | 1.5% | Aug 7, 2016 | Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors invol... |
| CVE-2016-5140 | — | — | 1.9% | Aug 7, 2016 | Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chro... |
| CVE-2016-5139 | — | — | 1.3% | Aug 7, 2016 | Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome be... |
| CVE-2016-1951 | — | — | 2.7% | Aug 7, 2016 | Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers ... |
| CVE-2016-6635 | — | — | 2.5% | Aug 7, 2016 | Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-ac... |
| CVE-2016-6634 | — | — | 2.5% | Aug 7, 2016 | Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to... |
| CVE-2016-5359 | — | — | 2.6% | Aug 7, 2016 | epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allow... |
| CVE-2016-5358 | — | — | 2.3% | Aug 7, 2016 | epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data... |
| CVE-2016-5357 | — | — | 2.5% | Aug 7, 2016 | wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles ssca... |
| CVE-2016-5356 | — | — | 2.5% | Aug 7, 2016 | wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf uns... |
| CVE-2016-5355 | — | — | 2.5% | Aug 7, 2016 | wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf u... |
| CVE-2016-5354 | — | — | 2.8% | Aug 7, 2016 | The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote at... |
| CVE-2016-5353 | — | — | 2.4% | Aug 7, 2016 | epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishan... |
| CVE-2016-5352 | — | — | 2.7% | Aug 7, 2016 | epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which... |
| CVE-2016-5351 | — | — | 2.4% | Aug 7, 2016 | epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles th... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now