2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1567 | — | — | 2.6% | Jan 26, 2016 | chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets,... |
| CVE-2016-1492 | — | — | 1.8% | Jan 26, 2016 | The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a pa... |
| CVE-2016-1491 | — | — | 2.5% | Jan 26, 2016 | The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password ... |
| CVE-2016-1490 | — | — | 1.7% | Jan 26, 2016 | The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a... |
| CVE-2016-1489 | — | — | 1.8% | Jan 26, 2016 | Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allo... |
| CVE-2016-1233 | — | — | 0.4% | Jan 26, 2016 | An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in ... |
| CVE-2016-0869 | — | — | 1.0% | Jan 26, 2016 | Heap-based buffer overflow in MICROSYS PROMOTIC before 8.3.11 allows remote authenticated users to cause a denial of ser... |
| CVE-2016-1298 | — | — | 1.1% | Jan 26, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), a... |
| CVE-2016-2052 | — | — | 1.0% | Jan 25, 2016 | Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attac... |
| CVE-2016-2051 | — | — | 1.0% | Jan 25, 2016 | Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow... |
| CVE-2016-1620 | — | — | 1.3% | Jan 25, 2016 | Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service o... |
| CVE-2016-1619 | — | — | 1.1% | Jan 25, 2016 | Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.... |
| CVE-2016-1618 | — | — | 1.3% | Jan 25, 2016 | Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random ... |
| CVE-2016-1617 | — | — | 1.3% | Jan 25, 2016 | The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP)... |
| CVE-2016-1616 | — | — | 1.1% | Jan 25, 2016 | The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.... |
| CVE-2016-1615 | — | — | 1.7% | Jan 25, 2016 | The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via... |
| CVE-2016-1614 | — | — | 1.0% | Jan 25, 2016 | The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blin... |
| CVE-2016-1613 | — | — | 1.1% | Jan 25, 2016 | Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0... |
| CVE-2016-1612 | — | — | 1.1% | Jan 25, 2016 | The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensur... |
| CVE-2016-1572 | HIGH | 8.4 | 0.4% | Jan 22, 2016 | mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local user... |
| CVE-2016-1571 | — | — | 1.3% | Jan 22, 2016 | The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nest... |
| CVE-2016-1570 | — | — | 1.2% | Jan 22, 2016 | The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to o... |
| CVE-2016-1984 | — | — | 4.1% | Jan 22, 2016 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the ... |
| CVE-2016-1135 | — | — | 0.8% | Jan 22, 2016 | Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices wi... |
| CVE-2016-1134 | — | — | 0.5% | Jan 22, 2016 | Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 dev... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now