2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1711——WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame...
CVE-2016-1710——The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome b...
CVE-2016-1709——Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly before 2016-06-10, as use...
CVE-2016-1708——The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82...
CVE-2016-1707——ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid U...
CVE-2016-1706——The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin...
CVE-2016-1705——Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.82 allow attackers to cause a denial of service o...
CVE-2016-6204——Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2...
CVE-2016-5874——Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outag...
CVE-2016-5744——Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted ...
CVE-2016-5743——Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed...
CVE-2016-6224——ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using G...
CVE-2016-4653——The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local user...
CVE-2016-4652——CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and cons...
CVE-2016-4651——Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9...
CVE-2016-4649——Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspec...
CVE-2016-4648——Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a de...
CVE-2016-4647——Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption...
CVE-2016-4646——Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive informatio...
CVE-2016-4645——CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain...
CVE-2016-4641——Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain s...
CVE-2016-4640——Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context, obtain sen...
CVE-2016-4639——Login Window in Apple OS X before 10.11.6 does not properly initialize memory, which allows local users to cause a denia...
CVE-2016-4638——Login Window in Apple OS X before 10.11.6 allows attackers to gain privileges via a crafted app that leverages a "type c...
CVE-2016-4637——CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now