2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2817 | — | — | 1.3% | Apr 30, 2016 | The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not pr... |
| CVE-2016-2816 | — | — | 2.3% | Apr 30, 2016 | Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via... |
| CVE-2016-2814 | — | — | 3.8% | Apr 30, 2016 | Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Fi... |
| CVE-2016-2813 | — | — | 1.4% | Apr 30, 2016 | Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, whic... |
| CVE-2016-2812 | — | — | 2.4% | Apr 30, 2016 | Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Fi... |
| CVE-2016-2811 | — | — | 2.9% | Apr 30, 2016 | Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46... |
| CVE-2016-2810 | — | — | 0.9% | Apr 30, 2016 | Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via ... |
| CVE-2016-2809 | — | — | 1.7% | Apr 30, 2016 | The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers ... |
| CVE-2016-2808 | — | — | 2.1% | Apr 30, 2016 | The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Fire... |
| CVE-2016-2807 | — | — | 4.7% | Apr 30, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8,... |
| CVE-2016-2806 | — | — | 4.7% | Apr 30, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45... |
| CVE-2016-2805 | — | — | 4.7% | Apr 30, 2016 | Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause... |
| CVE-2016-2804 | — | — | 4.8% | Apr 30, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to caus... |
| CVE-2016-1343 | — | — | 1.6% | Apr 30, 2016 | The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial o... |
| CVE-2016-1201 | — | — | 0.6% | Apr 30, 2016 | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack ... |
| CVE-2016-1200 | — | — | 0.9% | Apr 30, 2016 | The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access ... |
| CVE-2016-1199 | — | — | 1.3% | Apr 30, 2016 | The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended... |
| CVE-2016-1111 | — | — | 5.4% | Apr 30, 2016 | Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.00... |
| CVE-2016-4349 | — | — | 0.4% | Apr 28, 2016 | Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privile... |
| CVE-2016-1389 | — | — | 1.3% | Apr 28, 2016 | Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbit... |
| CVE-2016-1386 | — | — | 1.1% | Apr 28, 2016 | The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers... |
| CVE-2016-1205 | — | — | 1.0% | Apr 28, 2016 | Cross-site scripting (XSS) vulnerability in the shiro8 (1) category_freearea_ addition_plugin plugin 1.0 and (2) itemdet... |
| CVE-2016-0211 | — | — | 2.1% | Apr 28, 2016 | IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenti... |
| CVE-2016-3672 | — | — | 1.2% | Apr 27, 2016 | The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize t... |
| CVE-2016-3156 | — | — | 0.6% | Apr 27, 2016 | The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now