2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1944 | — | — | 3.7% | Jan 31, 2016 | The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attacker... |
| CVE-2016-1943 | — | — | 1.0% | Jan 31, 2016 | Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method. |
| CVE-2016-1942 | — | — | 1.8% | Jan 31, 2016 | Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by le... |
| CVE-2016-1941 | — | — | 0.9% | Jan 31, 2016 | The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remot... |
| CVE-2016-1940 | — | — | 0.7% | Jan 31, 2016 | Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandl... |
| CVE-2016-1939 | — | — | 1.8% | Jan 31, 2016 | Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers ... |
| CVE-2016-1938 | — | — | 3.1% | Jan 31, 2016 | The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla... |
| CVE-2016-1937 | — | — | 1.3% | Jan 31, 2016 | The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a... |
| CVE-2016-1935 | — | — | 5.1% | Jan 31, 2016 | Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows rem... |
| CVE-2016-1933 | — | — | 1.8% | Jan 31, 2016 | Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to caus... |
| CVE-2016-1931 | — | — | 5.7% | Jan 31, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to caus... |
| CVE-2016-1930 | — | — | 6.0% | Jan 31, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38... |
| CVE-2016-1985 | — | — | 6.6% | Jan 30, 2016 | HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serial... |
| CVE-2016-1145 | — | — | 3.8% | Jan 30, 2016 | Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3... |
| CVE-2016-1143 | — | — | 1.4% | Jan 30, 2016 | Cross-site scripting (XSS) vulnerability in main.rb in Vine MV before 2015-11-08 allows remote attackers to inject arbit... |
| CVE-2016-1141 | — | — | 1.0% | Jan 30, 2016 | KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified v... |
| CVE-2016-1140 | — | — | 1.0% | Jan 30, 2016 | KDDI HOME SPOT CUBE devices before 2 allow remote attackers to conduct clickjacking attacks via unspecified vectors. |
| CVE-2016-1139 | — | — | 0.6% | Jan 30, 2016 | Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijac... |
| CVE-2016-1138 | — | — | 1.1% | Jan 30, 2016 | CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP he... |
| CVE-2016-1137 | — | — | 1.3% | Jan 30, 2016 | Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitra... |
| CVE-2016-1136 | — | — | 0.8% | Jan 30, 2016 | Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to in... |
| CVE-2016-0867 | — | — | 2.2% | Jan 30, 2016 | CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request. |
| CVE-2016-1488 | — | — | 1.2% | Jan 30, 2016 | Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices be... |
| CVE-2016-1304 | — | — | 1.0% | Jan 30, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitr... |
| CVE-2016-1303 | — | — | 1.3% | Jan 30, 2016 | The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a craf... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now