2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1575 | HIGH | 7.8 | 0.9% | May 2, 2016 | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which al... |
| CVE-2016-4421 | — | — | 1.4% | May 1, 2016 | epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows r... |
| CVE-2016-4420 | — | — | 1.4% | May 1, 2016 | The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash)... |
| CVE-2016-4419 | — | — | 1.4% | May 1, 2016 | epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which al... |
| CVE-2016-4418 | — | — | 1.4% | May 1, 2016 | epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows r... |
| CVE-2016-4417 | — | — | 1.4% | May 1, 2016 | Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12... |
| CVE-2016-4416 | — | — | 1.1% | May 1, 2016 | epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping su... |
| CVE-2016-4415 | — | — | 1.7% | May 1, 2016 | wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet cou... |
| CVE-2016-2820 | — | — | 1.4% | Apr 30, 2016 | The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly rest... |
| CVE-2016-2817 | — | — | 1.3% | Apr 30, 2016 | The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not pr... |
| CVE-2016-2816 | — | — | 2.3% | Apr 30, 2016 | Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via... |
| CVE-2016-2814 | — | — | 3.8% | Apr 30, 2016 | Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Fi... |
| CVE-2016-2813 | — | — | 1.4% | Apr 30, 2016 | Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, whic... |
| CVE-2016-2812 | — | — | 2.4% | Apr 30, 2016 | Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Fi... |
| CVE-2016-2811 | — | — | 2.9% | Apr 30, 2016 | Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46... |
| CVE-2016-2810 | — | — | 0.9% | Apr 30, 2016 | Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via ... |
| CVE-2016-2809 | — | — | 1.7% | Apr 30, 2016 | The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers ... |
| CVE-2016-2808 | — | — | 2.1% | Apr 30, 2016 | The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Fire... |
| CVE-2016-2807 | — | — | 4.7% | Apr 30, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8,... |
| CVE-2016-2806 | — | — | 4.7% | Apr 30, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45... |
| CVE-2016-2805 | — | — | 4.7% | Apr 30, 2016 | Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause... |
| CVE-2016-2804 | — | — | 4.8% | Apr 30, 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to caus... |
| CVE-2016-1343 | — | — | 1.6% | Apr 30, 2016 | The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial o... |
| CVE-2016-1201 | — | — | 0.6% | Apr 30, 2016 | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack ... |
| CVE-2016-1200 | — | — | 0.9% | Apr 30, 2016 | The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now