2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0149 | — | — | 8.4% | May 11, 2016 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtai... |
| CVE-2016-0140 | — | — | 19.4% | May 11, 2016 | Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps ... |
| CVE-2016-0126 | — | — | 19.6% | May 11, 2016 | Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office ... |
| CVE-2016-4561 | — | — | 1.5% | May 10, 2016 | Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow rem... |
| CVE-2016-4556 | — | — | 23.1% | May 10, 2016 | Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a de... |
| CVE-2016-4555 | — | — | 53.9% | May 10, 2016 | client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of servi... |
| CVE-2016-4554 | — | — | 39.2% | May 10, 2016 | mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly c... |
| CVE-2016-4553 | — | — | 79.7% | May 10, 2016 | client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI i... |
| CVE-2016-4350 | — | — | 70.2% | May 9, 2016 | Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profi... |
| CVE-2016-3105 | — | — | 2.7% | May 9, 2016 | The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a cr... |
| CVE-2016-4477 | — | — | 0.3% | May 9, 2016 | wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users... |
| CVE-2016-2462 | — | — | 0.4% | May 9, 2016 | OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data... |
| CVE-2016-2461 | — | — | 0.5% | May 9, 2016 | OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data ... |
| CVE-2016-2460 | — | — | 0.4% | May 9, 2016 | mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not init... |
| CVE-2016-2459 | — | — | 0.4% | May 9, 2016 | mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not init... |
| CVE-2016-2458 | — | — | 0.5% | May 9, 2016 | The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does... |
| CVE-2016-2457 | — | — | 0.2% | May 9, 2016 | server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 ... |
| CVE-2016-2456 | — | — | 0.3% | May 9, 2016 | The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a ... |
| CVE-2016-2454 | — | — | 0.5% | May 9, 2016 | The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a den... |
| CVE-2016-2453 | — | — | 0.4% | May 9, 2016 | The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a ... |
| CVE-2016-2452 | — | — | 0.5% | May 9, 2016 | codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x bef... |
| CVE-2016-2451 | — | — | 0.4% | May 9, 2016 | codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x befor... |
| CVE-2016-2450 | — | — | 0.4% | May 9, 2016 | codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.... |
| CVE-2016-2449 | — | — | 0.4% | May 9, 2016 | services/camera/libcameraservice/device3/Camera3Device.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.... |
| CVE-2016-2448 | — | — | 0.4% | May 9, 2016 | media/libmediaplayerservice/nuplayer/NuPlayerStreamListener.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now