2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1374——The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authentica...
CVE-2016-3992——cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.e...
CVE-2016-6152——CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly ex...
CVE-2016-6151——CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands v...
CVE-2016-6297——Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24...
CVE-2016-6296——Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PH...
CVE-2016-6295——ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserializ...
CVE-2016-6294——The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and ...
CVE-2016-6293——The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 f...
CVE-2016-6292——The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0....
CVE-2016-6291——The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before ...
CVE-2016-6290——ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certa...
CVE-2016-6289——Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, a...
CVE-2016-6288——The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of se...
CVE-2016-5137——The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP)...
CVE-2016-5136——Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome...
CVE-2016-5135——WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not c...
CVE-2016-5134——net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure t...
CVE-2016-5133——Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-mid...
CVE-2016-5132——The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts speci...
CVE-2016-5131HIGH8.8Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attac...
CVE-2016-5130——content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of ...
CVE-2016-5129——Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed object...
CVE-2016-5128——objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API intercepto...
CVE-2016-5127——Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now