2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9061 | — | — | 1.6% | Jun 11, 2018 | A previously installed malicious Android application which defines a specific signature-level permissions used by Firefo... |
| CVE-2016-5299 | — | — | 1.6% | Jun 11, 2018 | A previously installed malicious Android application with same signature-level permissions as Firefox can intercept Auth... |
| CVE-2016-5298 | — | — | 1.3% | Jun 11, 2018 | A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to... |
| CVE-2016-5297 | — | — | 3.6% | Jun 11, 2018 | An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issu... |
| CVE-2016-5296 | — | — | 3.5% | Jun 11, 2018 | A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially ... |
| CVE-2016-5295 | — | — | 0.3% | Jun 11, 2018 | This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten... |
| CVE-2016-5294 | — | — | 0.4% | Jun 11, 2018 | The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda... |
| CVE-2016-5293 | — | — | 0.3% | Jun 11, 2018 | When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap... |
| CVE-2016-5292 | — | — | 1.5% | Jun 11, 2018 | During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire... |
| CVE-2016-5291 | — | — | 0.4% | Jun 11, 2018 | A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe... |
| CVE-2016-5290 | — | — | 3.2% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup... |
| CVE-2016-5289 | — | — | 2.0% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2016-5288 | — | — | 1.8% | Jun 11, 2018 | Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co... |
| CVE-2016-5287 | — | — | 2.4% | Jun 11, 2018 | A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect... |
| CVE-2016-9490 | — | — | 1.7% | Jun 5, 2018 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vul... |
| CVE-2016-9488 | — | — | 4.8% | Jun 5, 2018 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities... |
| CVE-2016-1000352 | — | — | 2.2% | Jun 4, 2018 | In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mo... |
| CVE-2016-1000346 | — | — | 2.3% | Jun 4, 2018 | In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This ca... |
| CVE-2016-1000345 | — | — | 2.6% | Jun 4, 2018 | In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.... |
| CVE-2016-1000344 | — | — | 2.2% | Jun 4, 2018 | In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mo... |
| CVE-2016-9042 | MEDIUM | 5.9 | 4.0% | Jun 4, 2018 | An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A spe... |
| CVE-2016-8390 | HIGH | 7.8 | 1.3% | Jun 4, 2018 | An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.1... |
| CVE-2016-10697 | — | — | 1.8% | Jun 4, 2018 | react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synt... |
| CVE-2016-10696 | — | — | 1.7% | Jun 4, 2018 | windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary... |
| CVE-2016-10695 | — | — | 1.8% | Jun 4, 2018 | The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now