2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3992 | — | — | 0.4% | Jul 26, 2016 | cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.e... |
| CVE-2016-6152 | — | — | 3.4% | Jul 26, 2016 | CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly ex... |
| CVE-2016-6151 | — | — | 2.7% | Jul 26, 2016 | CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands v... |
| CVE-2016-6297 | — | — | 5.3% | Jul 25, 2016 | Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24... |
| CVE-2016-6296 | — | — | 6.3% | Jul 25, 2016 | Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PH... |
| CVE-2016-6295 | — | — | 5.4% | Jul 25, 2016 | ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserializ... |
| CVE-2016-6294 | — | — | 6.0% | Jul 25, 2016 | The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and ... |
| CVE-2016-6293 | — | — | 5.0% | Jul 25, 2016 | The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 f... |
| CVE-2016-6292 | — | — | 3.9% | Jul 25, 2016 | The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.... |
| CVE-2016-6291 | — | — | 5.6% | Jul 25, 2016 | The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before ... |
| CVE-2016-6290 | — | — | 5.5% | Jul 25, 2016 | ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certa... |
| CVE-2016-6289 | — | — | 3.8% | Jul 25, 2016 | Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, a... |
| CVE-2016-6288 | — | — | 5.1% | Jul 25, 2016 | The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of se... |
| CVE-2016-5137 | — | — | 1.3% | Jul 23, 2016 | The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP)... |
| CVE-2016-5136 | — | — | 1.4% | Jul 23, 2016 | Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome... |
| CVE-2016-5135 | — | — | 1.6% | Jul 23, 2016 | WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not c... |
| CVE-2016-5134 | — | — | 1.5% | Jul 23, 2016 | net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure t... |
| CVE-2016-5133 | — | — | 1.0% | Jul 23, 2016 | Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-mid... |
| CVE-2016-5132 | — | — | 1.4% | Jul 23, 2016 | The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts speci... |
| CVE-2016-5131 | HIGH | 8.8 | 2.3% | Jul 23, 2016 | Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attac... |
| CVE-2016-5130 | — | — | 1.2% | Jul 23, 2016 | content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of ... |
| CVE-2016-5129 | — | — | 2.1% | Jul 23, 2016 | Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed object... |
| CVE-2016-5128 | — | — | 1.3% | Jul 23, 2016 | objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API intercepto... |
| CVE-2016-5127 | — | — | 1.3% | Jul 23, 2016 | Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52... |
| CVE-2016-1711 | — | — | 1.5% | Jul 23, 2016 | WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now