2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0087 | — | — | 1.6% | Mar 9, 2016 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly validate handles, whi... |
| CVE-2016-0057 | — | — | 1.5% | Mar 9, 2016 | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows ... |
| CVE-2016-0021 | — | — | 23.4% | Mar 9, 2016 | Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Offi... |
| CVE-2016-2845 | — | — | 2.2% | Mar 6, 2016 | The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore... |
| CVE-2016-2844 | — | — | 2.1% | Mar 6, 2016 | WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly dete... |
| CVE-2016-2843 | — | — | 1.1% | Mar 6, 2016 | Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow... |
| CVE-2016-1642 | — | — | 1.6% | Mar 6, 2016 | Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a denial of service o... |
| CVE-2016-1641 | — | — | 1.9% | Mar 6, 2016 | Use-after-free vulnerability in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 49.0.2623.75 a... |
| CVE-2016-1640 | — | — | 1.1% | Mar 6, 2016 | The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block i... |
| CVE-2016-1639 | — | — | 2.3% | Mar 6, 2016 | Use-after-free vulnerability in browser/extensions/api/webrtc_audio_private/webrtc_audio_private_api.cc in the WebRTC Au... |
| CVE-2016-1638 | — | — | 1.1% | Mar 6, 2016 | extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not ... |
| CVE-2016-1637 | — | — | 1.1% | Mar 6, 2016 | The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75,... |
| CVE-2016-1636 | — | — | 1.8% | Mar 6, 2016 | The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623... |
| CVE-2016-1635 | — | — | 2.3% | Mar 6, 2016 | extensions/renderer/render_frame_observer_natives.cc in Google Chrome before 49.0.2623.75 does not properly consider obj... |
| CVE-2016-1634 | — | — | 1.6% | Mar 6, 2016 | Use-after-free vulnerability in the StyleResolver::appendCSSStyleSheet function in WebKit/Source/core/css/resolver/Style... |
| CVE-2016-1633 | — | — | 2.5% | Mar 6, 2016 | Use-after-free vulnerability in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a ... |
| CVE-2016-1632 | — | — | 1.3% | Mar 6, 2016 | The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows re... |
| CVE-2016-1631 | — | — | 1.3% | Mar 6, 2016 | The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pe... |
| CVE-2016-1630 | — | — | 1.1% | Mar 6, 2016 | The ContainerNode::parserRemoveChild function in WebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Ch... |
| CVE-2016-2283 | — | — | 1.2% | Mar 4, 2016 | Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which... |
| CVE-2016-2282 | — | — | 1.7% | Mar 4, 2016 | Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials... |
| CVE-2016-2244 | — | — | 3.2% | Mar 4, 2016 | HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to ob... |
| CVE-2016-2243 | — | — | 0.4% | Mar 4, 2016 | Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveragi... |
| CVE-2016-1359 | — | — | 2.2% | Mar 3, 2016 | Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request th... |
| CVE-2016-1358 | — | — | 1.3% | Mar 3, 2016 | Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a d... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now