2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1670 | — | — | 0.9% | May 14, 2016 | Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_ho... |
| CVE-2016-1669 | HIGH | 8.8 | 4.2% | May 14, 2016 | The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not... |
| CVE-2016-1668 | — | — | 1.3% | May 14, 2016 | The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Goog... |
| CVE-2016-1667 | — | — | 2.1% | May 14, 2016 | The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as use... |
| CVE-2016-1666 | — | — | 1.4% | May 14, 2016 | Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service o... |
| CVE-2016-1665 | — | — | 1.8% | May 14, 2016 | The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.9... |
| CVE-2016-1664 | — | — | 1.0% | May 14, 2016 | The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2... |
| CVE-2016-1663 | — | — | 1.0% | May 14, 2016 | The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in ... |
| CVE-2016-1662 | — | — | 3.9% | May 14, 2016 | extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Gar... |
| CVE-2016-1661 | — | — | 1.2% | May 14, 2016 | Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer p... |
| CVE-2016-1660 | — | — | 1.1% | May 14, 2016 | Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversi... |
| CVE-2016-4325 | — | — | 2.5% | May 14, 2016 | Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers t... |
| CVE-2016-2298 | — | — | 24.1% | May 14, 2016 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext info... |
| CVE-2016-2297 | — | — | 4.4% | May 14, 2016 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via ... |
| CVE-2016-2296 | — | — | 64.4% | May 14, 2016 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag... |
| CVE-2016-1207 | — | — | 0.8% | May 14, 2016 | Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 d... |
| CVE-2016-1206 | — | — | 0.6% | May 14, 2016 | The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PI... |
| CVE-2016-2016 | — | — | 0.5% | May 14, 2016 | Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 thro... |
| CVE-2016-2015 | — | — | 0.5% | May 14, 2016 | HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspec... |
| CVE-2016-1209 | — | — | 61.6% | May 14, 2016 | The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via... |
| CVE-2016-1208 | — | — | 1.3% | May 14, 2016 | The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vect... |
| CVE-2016-1399 | — | — | 2.5% | May 14, 2016 | The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 400... |
| CVE-2016-4536 | — | — | 1.3% | May 13, 2016 | The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) V... |
| CVE-2016-4024 | — | — | 5.8% | May 13, 2016 | Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large ... |
| CVE-2016-3994 | — | — | 2.8% | May 13, 2016 | The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now