2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1233 | — | — | 0.4% | Jan 26, 2016 | An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in ... |
| CVE-2016-0869 | — | — | 1.0% | Jan 26, 2016 | Heap-based buffer overflow in MICROSYS PROMOTIC before 8.3.11 allows remote authenticated users to cause a denial of ser... |
| CVE-2016-1298 | — | — | 1.1% | Jan 26, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), a... |
| CVE-2016-2052 | — | — | 1.0% | Jan 25, 2016 | Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attac... |
| CVE-2016-2051 | — | — | 1.0% | Jan 25, 2016 | Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow... |
| CVE-2016-1620 | — | — | 1.3% | Jan 25, 2016 | Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service o... |
| CVE-2016-1619 | — | — | 1.1% | Jan 25, 2016 | Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.... |
| CVE-2016-1618 | — | — | 1.3% | Jan 25, 2016 | Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random ... |
| CVE-2016-1617 | — | — | 1.3% | Jan 25, 2016 | The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP)... |
| CVE-2016-1616 | — | — | 1.1% | Jan 25, 2016 | The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.... |
| CVE-2016-1615 | — | — | 1.7% | Jan 25, 2016 | The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via... |
| CVE-2016-1614 | — | — | 1.0% | Jan 25, 2016 | The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blin... |
| CVE-2016-1613 | — | — | 1.1% | Jan 25, 2016 | Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0... |
| CVE-2016-1612 | — | — | 1.1% | Jan 25, 2016 | The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensur... |
| CVE-2016-1571 | — | — | 1.3% | Jan 22, 2016 | The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nest... |
| CVE-2016-1570 | — | — | 1.2% | Jan 22, 2016 | The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to o... |
| CVE-2016-1984 | — | — | 4.1% | Jan 22, 2016 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the ... |
| CVE-2016-1135 | — | — | 0.8% | Jan 22, 2016 | Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices wi... |
| CVE-2016-1134 | — | — | 0.5% | Jan 22, 2016 | Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 dev... |
| CVE-2016-0618 | — | — | 0.4% | Jan 21, 2016 | Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors rela... |
| CVE-2016-0616 | — | — | 3.8% | Jan 21, 2016 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.... |
| CVE-2016-0614 | — | — | 1.4% | Jan 21, 2016 | Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 1... |
| CVE-2016-0611 | — | — | 3.2% | Jan 21, 2016 | Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect avail... |
| CVE-2016-0610 | — | — | 2.6% | Jan 21, 2016 | Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows ... |
| CVE-2016-0609 | — | — | 3.9% | Jan 21, 2016 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 1... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now