2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9074 | — | — | 2.5% | Jun 11, 2018 | An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in ... |
| CVE-2016-9073 | — | — | 1.7% | Jun 11, 2018 | WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This v... |
| CVE-2016-9072 | — | — | 1.3% | Jun 11, 2018 | When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabl... |
| CVE-2016-9071 | — | — | 1.9% | Jun 11, 2018 | Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know... |
| CVE-2016-9070 | — | — | 1.9% | Jun 11, 2018 | A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage ... |
| CVE-2016-9068 | — | — | 2.0% | Jun 11, 2018 | A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vu... |
| CVE-2016-9067 | — | — | 1.9% | Jun 11, 2018 | Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects... |
| CVE-2016-9066 | — | — | 12.4% | Jun 11, 2018 | A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amoun... |
| CVE-2016-9065 | — | — | 1.9% | Jun 11, 2018 | The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and... |
| CVE-2016-9064 | — | — | 1.0% | Jun 11, 2018 | Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated.... |
| CVE-2016-9062 | — | — | 0.4% | Jun 11, 2018 | Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" ... |
| CVE-2016-9061 | — | — | 1.6% | Jun 11, 2018 | A previously installed malicious Android application which defines a specific signature-level permissions used by Firefo... |
| CVE-2016-5299 | — | — | 1.6% | Jun 11, 2018 | A previously installed malicious Android application with same signature-level permissions as Firefox can intercept Auth... |
| CVE-2016-5298 | — | — | 1.3% | Jun 11, 2018 | A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to... |
| CVE-2016-5297 | — | — | 3.6% | Jun 11, 2018 | An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issu... |
| CVE-2016-5296 | — | — | 3.5% | Jun 11, 2018 | A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially ... |
| CVE-2016-5295 | — | — | 0.3% | Jun 11, 2018 | This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten... |
| CVE-2016-5294 | — | — | 0.4% | Jun 11, 2018 | The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda... |
| CVE-2016-5293 | — | — | 0.3% | Jun 11, 2018 | When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap... |
| CVE-2016-5292 | — | — | 1.5% | Jun 11, 2018 | During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire... |
| CVE-2016-5291 | — | — | 0.4% | Jun 11, 2018 | A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe... |
| CVE-2016-5290 | — | — | 3.2% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup... |
| CVE-2016-5289 | — | — | 2.0% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2016-5288 | — | — | 1.8% | Jun 11, 2018 | Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co... |
| CVE-2016-5287 | — | — | 2.4% | Jun 11, 2018 | A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now