2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1905 | — | — | 1.6% | Feb 3, 2016 | The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to acces... |
| CVE-2016-1505 | — | — | 2.6% | Feb 3, 2016 | The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary f... |
| CVE-2016-2213 | — | — | 1.9% | Feb 3, 2016 | The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a ... |
| CVE-2016-7028 | — | — | — | Feb 1, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0728. Reason: This candidate is a duplicate of... |
| CVE-2016-2199 | — | — | 0.5% | Feb 1, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enter... |
| CVE-2016-2049 | — | — | 2.2% | Feb 1, 2016 | examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter... |
| CVE-2016-1730 | — | — | 1.3% | Feb 1, 2016 | WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive po... |
| CVE-2016-1729 | — | — | 1.3% | Feb 1, 2016 | Untrusted search path vulnerability in OSA Scripts in Apple OS X before 10.11.3 allows attackers to load arbitrary scrip... |
| CVE-2016-1728 | — | — | 1.7% | Feb 1, 2016 | The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visi... |
| CVE-2016-1727 | — | — | 4.5% | Feb 1, 2016 | WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execut... |
| CVE-2016-1726 | — | — | 4.5% | Feb 1, 2016 | WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or ... |
| CVE-2016-1725 | — | — | 4.5% | Feb 1, 2016 | WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or ... |
| CVE-2016-1724 | — | — | 2.6% | Feb 1, 2016 | WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execut... |
| CVE-2016-1723 | — | — | 4.5% | Feb 1, 2016 | WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or ... |
| CVE-2016-1722 | — | — | 0.3% | Feb 1, 2016 | syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or ca... |
| CVE-2016-1721 | — | — | 1.0% | Feb 1, 2016 | The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o... |
| CVE-2016-1720 | — | — | 1.0% | Feb 1, 2016 | IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cau... |
| CVE-2016-1719 | — | — | 1.2% | Feb 1, 2016 | The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri... |
| CVE-2016-1718 | — | — | 0.4% | Feb 1, 2016 | The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privil... |
| CVE-2016-1717 | — | — | 0.3% | Feb 1, 2016 | The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to ga... |
| CVE-2016-1716 | — | — | 0.3% | Feb 1, 2016 | AppleGraphicsPowerManagement in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of ser... |
| CVE-2016-1948 | — | — | 0.5% | Jan 31, 2016 | Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which al... |
| CVE-2016-1947 | — | — | 1.9% | Jan 31, 2016 | Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for rem... |
| CVE-2016-1946 | — | — | 5.6% | Jan 31, 2016 | The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not li... |
| CVE-2016-1945 | — | — | 3.0% | Jan 31, 2016 | The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or po... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now