2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9061A previously installed malicious Android application which defines a specific signature-level permissions used by Firefo...
CVE-2016-5299A previously installed malicious Android application with same signature-level permissions as Firefox can intercept Auth...
CVE-2016-5298A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to...
CVE-2016-5297An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issu...
CVE-2016-5296A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially ...
CVE-2016-5295This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten...
CVE-2016-5294The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda...
CVE-2016-5293When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap...
CVE-2016-5292During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire...
CVE-2016-5291A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe...
CVE-2016-5290Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup...
CVE-2016-5289Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2016-5288Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co...
CVE-2016-5287A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect...
CVE-2016-9490ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vul...
CVE-2016-9488ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities...
CVE-2016-1000352In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mo...
CVE-2016-1000346In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This ca...
CVE-2016-1000345In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack....
CVE-2016-1000344In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mo...
CVE-2016-9042MEDIUM5.9An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A spe...
CVE-2016-8390HIGH7.8An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.1...
CVE-2016-10697react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synt...
CVE-2016-10696windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary...
CVE-2016-10695The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now