2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9900——External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of ...
CVE-2016-9899——Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption....
CVE-2016-9898——Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerabili...
CVE-2016-9897——Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a ...
CVE-2016-9896——Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. ...
CVE-2016-9895——Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline...
CVE-2016-9894——A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buf...
CVE-2016-9893——Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we pre...
CVE-2016-9080——Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presu...
CVE-2016-9079HIGH7.5A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis...
CVE-2016-9078——Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circ...
CVE-2016-9077——Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is va...
CVE-2016-9076——An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing att...
CVE-2016-9075——An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed ...
CVE-2016-9074——An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in ...
CVE-2016-9073——WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This v...
CVE-2016-9072——When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabl...
CVE-2016-9071——Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know...
CVE-2016-9070——A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage ...
CVE-2016-9068——A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vu...
CVE-2016-9067——Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects...
CVE-2016-9066——A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amoun...
CVE-2016-9065——The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and...
CVE-2016-9064——Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated....
CVE-2016-9063CRITICAL9.8An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now