2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-2018HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information or modify data vi...
CVE-2016-2017HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modi...
CVE-2016-1418Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local ...
CVE-2016-1405libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance...
CVE-2016-4545Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service ...
CVE-2016-3093Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which ...
CVE-2016-3087Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a...
CVE-2016-3072Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb...
CVE-2016-5242The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the dr...
CVE-2016-4963The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a d...
CVE-2016-4962The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (re...
CVE-2016-4450HIGH7.5os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service...
CVE-2016-4437CRITICAL9.8Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack...
CVE-2016-2335The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attacke...
CVE-2016-4347Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7558. Reason: This candidate is a reservation ...
CVE-2016-1703Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service o...
CVE-2016-1702The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does n...
CVE-2016-1701The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and Ja...
CVE-2016-1700extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects durin...
CVE-2016-1699WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google...
CVE-2016-1698The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome bef...
CVE-2016-1697The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome befo...
CVE-2016-1696The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows r...
CVE-2016-1695Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service o...
CVE-2016-1694browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clear...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now