2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4911MEDIUM4.3The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users...
CVE-2016-4005The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users...
CVE-2016-3677The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local use...
CVE-2016-3670Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1...
CVE-2016-2174SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administr...
CVE-2016-1543The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a...
CVE-2016-1542The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U...
CVE-2016-2834Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to ...
CVE-2016-2833Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes ...
CVE-2016-2832Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack...
CVE-2016-2831Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and poi...
CVE-2016-2829Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidl...
CVE-2016-2828Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to ...
CVE-2016-2826The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR ...
CVE-2016-2825Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host proper...
CVE-2016-2824The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows...
CVE-2016-2822Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELEC...
CVE-2016-2821Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x befo...
CVE-2016-2819Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to ex...
CVE-2016-2818Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45...
CVE-2016-2815Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to caus...
CVE-2016-2500Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminat...
CVE-2016-2499AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, an...
CVE-2016-2498The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended dat...
CVE-2016-2496CRITICAL9.8The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjackin...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now