2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6562 | — | — | 0.4% | Jul 13, 2018 | On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificat... |
| CVE-2016-6559 | — | — | 3.7% | Jul 13, 2018 | Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allo... |
| CVE-2016-6558 | — | — | 3.5% | Jul 13, 2018 | A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and po... |
| CVE-2016-6557 | — | — | 0.9% | Jul 13, 2018 | In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface ... |
| CVE-2016-6554 | — | — | 4.1% | Jul 13, 2018 | Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1... |
| CVE-2016-6553 | — | — | 2.9% | Jul 13, 2018 | Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and local... |
| CVE-2016-6552 | — | — | 2.9% | Jul 13, 2018 | Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged ac... |
| CVE-2016-6551 | — | — | 2.9% | Jul 13, 2018 | Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ft... |
| CVE-2016-6549 | — | — | 1.1% | Jul 13, 2018 | The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications... |
| CVE-2016-6548 | — | — | 3.7% | Jul 13, 2018 | The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated ... |
| CVE-2016-6547 | — | — | 0.4% | Jul 13, 2018 | The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cach... |
| CVE-2016-6546 | — | — | 0.4% | Jul 13, 2018 | The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding ... |
| CVE-2016-6545 | — | — | 3.1% | Jul 13, 2018 | Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST para... |
| CVE-2016-6544 | — | — | 3.4% | Jul 13, 2018 | getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps... |
| CVE-2016-6543 | — | — | 2.2% | Jul 13, 2018 | A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS ... |
| CVE-2016-6542 | — | — | 1.8% | Jul 13, 2018 | The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an... |
| CVE-2016-0708 | — | — | 1.6% | Jul 11, 2018 | Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat... |
| CVE-2016-10726 | — | — | 2.9% | Jul 10, 2018 | The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ pa... |
| CVE-2016-5015 | — | — | — | Jul 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-4466 | — | — | — | Jul 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-6541 | — | — | 1.1% | Jul 6, 2018 | TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to var... |
| CVE-2016-6540 | — | — | 0.9% | Jul 6, 2018 | Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data... |
| CVE-2016-6539 | — | — | 1.3% | Jul 6, 2018 | The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever... |
| CVE-2016-6538 | — | — | 1.1% | Jul 6, 2018 | The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.... |
| CVE-2016-10725 | — | — | 2.5% | Jul 5, 2018 | In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to overr... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now