2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10724 | — | — | 2.3% | Jul 5, 2018 | Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (d... |
| CVE-2016-10545 | — | — | — | Jul 5, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-10522 | — | — | 1.0% | Jul 5, 2018 | rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not valida... |
| CVE-2016-10723 | — | — | 0.4% | Jun 21, 2018 | An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the... |
| CVE-2016-1000025 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10542. Reason: This candidate is a reservation ... |
| CVE-2016-1000023 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation ... |
| CVE-2016-1000013 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10531. Reason: This candidate is a reservation ... |
| CVE-2016-9905 | — | — | 2.4% | Jun 11, 2018 | A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af... |
| CVE-2016-9904 | — | — | 2.8% | Jun 11, 2018 | An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon... |
| CVE-2016-9903 | — | — | 1.1% | Jun 11, 2018 | Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili... |
| CVE-2016-9902 | — | — | 1.3% | Jun 11, 2018 | The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o... |
| CVE-2016-9901 | — | — | 2.9% | Jun 11, 2018 | HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b... |
| CVE-2016-9900 | — | — | 9.9% | Jun 11, 2018 | External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of ... |
| CVE-2016-9899 | — | — | 21.4% | Jun 11, 2018 | Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.... |
| CVE-2016-9898 | — | — | 3.6% | Jun 11, 2018 | Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerabili... |
| CVE-2016-9897 | — | — | 3.3% | Jun 11, 2018 | Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a ... |
| CVE-2016-9896 | — | — | 2.0% | Jun 11, 2018 | Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. ... |
| CVE-2016-9895 | — | — | 1.8% | Jun 11, 2018 | Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline... |
| CVE-2016-9894 | — | — | 5.1% | Jun 11, 2018 | A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buf... |
| CVE-2016-9893 | — | — | 2.6% | Jun 11, 2018 | Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we pre... |
| CVE-2016-9080 | — | — | 2.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presu... |
| CVE-2016-9078 | — | — | 1.9% | Jun 11, 2018 | Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circ... |
| CVE-2016-9077 | — | — | 0.8% | Jun 11, 2018 | Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is va... |
| CVE-2016-9076 | — | — | 1.8% | Jun 11, 2018 | An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing att... |
| CVE-2016-9075 | — | — | 2.2% | Jun 11, 2018 | An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now