2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-9074An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in ...
CVE-2016-9073WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This v...
CVE-2016-9072When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabl...
CVE-2016-9071Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know...
CVE-2016-9070A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage ...
CVE-2016-9068A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vu...
CVE-2016-9067Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects...
CVE-2016-9066A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amoun...
CVE-2016-9065The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and...
CVE-2016-9064Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated....
CVE-2016-9062Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" ...
CVE-2016-9061A previously installed malicious Android application which defines a specific signature-level permissions used by Firefo...
CVE-2016-5299A previously installed malicious Android application with same signature-level permissions as Firefox can intercept Auth...
CVE-2016-5298A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to...
CVE-2016-5297An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issu...
CVE-2016-5296A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially ...
CVE-2016-5295This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten...
CVE-2016-5294The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda...
CVE-2016-5293When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap...
CVE-2016-5292During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire...
CVE-2016-5291A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe...
CVE-2016-5290Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup...
CVE-2016-5289Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2016-5288Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co...
CVE-2016-5287A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now