2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-6562——On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificat...
CVE-2016-6559——Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allo...
CVE-2016-6558——A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and po...
CVE-2016-6557——In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface ...
CVE-2016-6554——Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1...
CVE-2016-6553——Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and local...
CVE-2016-6552——Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged ac...
CVE-2016-6551——Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ft...
CVE-2016-6549——The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications...
CVE-2016-6548——The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated ...
CVE-2016-6547——The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cach...
CVE-2016-6546——The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding ...
CVE-2016-6545——Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST para...
CVE-2016-6544——getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps...
CVE-2016-6543——A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS ...
CVE-2016-6542——The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an...
CVE-2016-0708——Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat...
CVE-2016-10726——The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ pa...
CVE-2016-5015——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-4466——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6541——TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to var...
CVE-2016-6540——Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data...
CVE-2016-6539——The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever...
CVE-2016-6538——The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache....
CVE-2016-10725——In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to overr...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now