2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5273 | — | — | 1.8% | Sep 22, 2016 | The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox b... |
| CVE-2016-5272 | — | — | 2.2% | Sep 22, 2016 | The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does... |
| CVE-2016-5271 | — | — | 1.4% | Sep 22, 2016 | The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a deni... |
| CVE-2016-5270 | — | — | 3.9% | Sep 22, 2016 | Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0... |
| CVE-2016-5257 | — | — | 4.2% | Sep 22, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 ... |
| CVE-2016-5256 | — | — | 3.8% | Sep 22, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to caus... |
| CVE-2016-2827 | — | — | 1.7% | Sep 22, 2016 | The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denia... |
| CVE-2016-6824 | — | — | 1.0% | Sep 22, 2016 | Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenti... |
| CVE-2016-6669 | — | — | 3.3% | Sep 22, 2016 | Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, an... |
| CVE-2016-6525 | — | — | 3.8% | Sep 22, 2016 | Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to c... |
| CVE-2016-6340 | — | — | 0.4% | Sep 22, 2016 | The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which ma... |
| CVE-2016-6322 | — | — | 0.4% | Sep 22, 2016 | Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users ... |
| CVE-2016-6265 | — | — | 1.6% | Sep 22, 2016 | Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a... |
| CVE-2016-5247 | — | — | 0.4% | Sep 22, 2016 | The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, ... |
| CVE-2016-4464 | — | — | 4.0% | Sep 21, 2016 | The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestrict... |
| CVE-2016-3991 | — | — | 3.9% | Sep 21, 2016 | Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote att... |
| CVE-2016-3990 | — | — | 3.9% | Sep 21, 2016 | Heap-based buffer overflow in the horizontalDifference8 function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows r... |
| CVE-2016-3945 | — | — | 3.4% | Sep 21, 2016 | Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 ... |
| CVE-2016-3632 | — | — | 3.1% | Sep 21, 2016 | The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s... |
| CVE-2016-7166 | — | — | 1.6% | Sep 21, 2016 | libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a ... |
| CVE-2016-7154 | — | — | 0.5% | Sep 21, 2016 | Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a... |
| CVE-2016-7143 | — | — | 1.1% | Sep 21, 2016 | The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate f... |
| CVE-2016-7094 | — | — | 0.4% | Sep 21, 2016 | Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow pagi... |
| CVE-2016-7093 | — | — | 0.4% | Sep 21, 2016 | Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain... |
| CVE-2016-7092 | — | — | 0.4% | Sep 21, 2016 | The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS pr... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now