2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-3250——The kernel-mode drivers in Microsoft Windows Server 2012 and Windows 10 Gold and 1511 allow local users to gain privileg...
CVE-2016-3249——The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, ...
CVE-2016-3248——The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 t...
CVE-2016-3246——Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a ...
CVE-2016-3245——Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restric...
CVE-2016-3244——Microsoft Edge allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Ed...
CVE-2016-3243——Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me...
CVE-2016-3242——Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2016-3241——Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2016-3240——Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2016-3239——The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1...
CVE-2016-3238——The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1...
CVE-2016-3204——The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and ...
CVE-2016-6174——applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo...
CVE-2016-5850——Cross-site scripting (XSS) vulnerability in the volume backup service module in Huawei Public Cloud Solution before 1.0....
CVE-2016-5774——The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensit...
CVE-2016-5009——The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (se...
CVE-2016-4994HIGH7.8Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cau...
CVE-2016-4985——The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers ...
CVE-2016-4428MEDIUM5.4Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allo...
CVE-2016-2219——Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allow...
CVE-2016-5781——Stack-based buffer overflow in WECON LeviStudio allows remote attackers to execute arbitrary code via a crafted file.
CVE-2016-5308——The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1....
CVE-2016-4831——Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain p...
CVE-2016-4533HIGH7.8Heap-based buffer overflow in WECON LeviStudio allows remote attackers to execute arbitrary code via a crafted file.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now