2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1710The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome b...
CVE-2016-1709Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly before 2016-06-10, as use...
CVE-2016-1708The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82...
CVE-2016-1707ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid U...
CVE-2016-1706The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin...
CVE-2016-1705Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.82 allow attackers to cause a denial of service o...
CVE-2016-6204Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2...
CVE-2016-5874Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outag...
CVE-2016-5744Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted ...
CVE-2016-5743Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed...
CVE-2016-6224ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using G...
CVE-2016-4653The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local user...
CVE-2016-4652CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and cons...
CVE-2016-4651Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9...
CVE-2016-4649Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspec...
CVE-2016-4648Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a de...
CVE-2016-4647Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption...
CVE-2016-4646Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive informatio...
CVE-2016-4645CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain...
CVE-2016-4641Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain s...
CVE-2016-4640Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context, obtain sen...
CVE-2016-4639Login Window in Apple OS X before 10.11.6 does not properly initialize memory, which allows local users to cause a denia...
CVE-2016-4638Login Window in Apple OS X before 10.11.6 allows attackers to gain privileges via a crafted app that leverages a "type c...
CVE-2016-4637CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a...
CVE-2016-4635FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call term...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now