2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6543 | — | — | 2.2% | Jul 13, 2018 | A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS ... |
| CVE-2016-6542 | — | — | 1.8% | Jul 13, 2018 | The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an... |
| CVE-2016-0708 | — | — | 1.6% | Jul 11, 2018 | Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat... |
| CVE-2016-9604 | MEDIUM | 4.4 | 0.3% | Jul 11, 2018 | It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '... |
| CVE-2016-10726 | — | — | 2.9% | Jul 10, 2018 | The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ pa... |
| CVE-2016-5015 | — | — | — | Jul 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-4466 | — | — | — | Jul 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-6541 | — | — | 1.1% | Jul 6, 2018 | TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to var... |
| CVE-2016-6540 | — | — | 0.9% | Jul 6, 2018 | Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data... |
| CVE-2016-6539 | — | — | 1.3% | Jul 6, 2018 | The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever... |
| CVE-2016-6538 | — | — | 1.1% | Jul 6, 2018 | The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.... |
| CVE-2016-10725 | — | — | 2.5% | Jul 5, 2018 | In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to overr... |
| CVE-2016-10724 | — | — | 2.3% | Jul 5, 2018 | Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (d... |
| CVE-2016-10545 | — | — | — | Jul 5, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-10522 | — | — | 1.0% | Jul 5, 2018 | rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not valida... |
| CVE-2016-10723 | — | — | 0.4% | Jun 21, 2018 | An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the... |
| CVE-2016-1000025 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10542. Reason: This candidate is a reservation ... |
| CVE-2016-1000023 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation ... |
| CVE-2016-1000013 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10531. Reason: This candidate is a reservation ... |
| CVE-2016-9905 | — | — | 2.4% | Jun 11, 2018 | A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af... |
| CVE-2016-9904 | — | — | 2.8% | Jun 11, 2018 | An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon... |
| CVE-2016-9903 | — | — | 1.1% | Jun 11, 2018 | Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili... |
| CVE-2016-9902 | — | — | 1.3% | Jun 11, 2018 | The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o... |
| CVE-2016-9901 | — | — | 2.9% | Jun 11, 2018 | HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b... |
| CVE-2016-9900 | — | — | 9.9% | Jun 11, 2018 | External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now