2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3196 | — | — | 1.0% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiMan... |
| CVE-2016-3097 | — | — | 1.1% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject ar... |
| CVE-2016-3080 | — | — | 1.1% | Aug 5, 2016 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject ar... |
| CVE-2016-1513 | — | — | 4.4% | Aug 5, 2016 | The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bou... |
| CVE-2016-5268 | — | — | 1.2% | Aug 5, 2016 | Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs t... |
| CVE-2016-5267 | — | — | 0.9% | Aug 5, 2016 | Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in ... |
| CVE-2016-5266 | — | — | 1.7% | Aug 5, 2016 | Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which al... |
| CVE-2016-5265 | — | — | 1.3% | Aug 5, 2016 | Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Ori... |
| CVE-2016-5264 | — | — | 3.2% | Aug 5, 2016 | Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 ... |
| CVE-2016-5263 | — | — | 2.3% | Aug 5, 2016 | The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering... |
| CVE-2016-5262 | — | — | 1.5% | Aug 5, 2016 | Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE el... |
| CVE-2016-5261 | — | — | 4.1% | Aug 5, 2016 | Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ES... |
| CVE-2016-5260 | — | — | 1.4% | Aug 5, 2016 | Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Sessi... |
| CVE-2016-5259 | — | — | 3.3% | Aug 5, 2016 | Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR... |
| CVE-2016-5258 | — | — | 3.3% | Aug 5, 2016 | Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3... |
| CVE-2016-5255 | — | — | 2.4% | Aug 5, 2016 | Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows rem... |
| CVE-2016-5254 | — | — | 3.0% | Aug 5, 2016 | Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 4... |
| CVE-2016-5253 | — | — | 0.2% | Aug 5, 2016 | The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involvi... |
| CVE-2016-5252 | — | — | 3.1% | Aug 5, 2016 | Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45... |
| CVE-2016-5251 | — | — | 1.5% | Aug 5, 2016 | Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type o... |
| CVE-2016-5250 | — | — | 2.2% | Aug 5, 2016 | Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive inform... |
| CVE-2016-2839 | — | — | 1.8% | Aug 5, 2016 | Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that d... |
| CVE-2016-2838 | — | — | 4.5% | Aug 5, 2016 | Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ES... |
| CVE-2016-2837 | — | — | 4.6% | Aug 5, 2016 | Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API i... |
| CVE-2016-2836 | — | — | 2.9% | Aug 5, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now