2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6544——getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps...
CVE-2016-6543——A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS ...
CVE-2016-6542——The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an...
CVE-2016-0708——Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat...
CVE-2016-9604MEDIUM4.4It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '...
CVE-2016-10726——The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ pa...
CVE-2016-5015——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-4466——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6541——TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to var...
CVE-2016-6540——Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data...
CVE-2016-6539——The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever...
CVE-2016-6538——The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache....
CVE-2016-10725——In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to overr...
CVE-2016-10724——Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (d...
CVE-2016-10545——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-10522——rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not valida...
CVE-2016-10723——An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the...
CVE-2016-1000025——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10542. Reason: This candidate is a reservation ...
CVE-2016-1000023——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation ...
CVE-2016-1000013——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10531. Reason: This candidate is a reservation ...
CVE-2016-9905——A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af...
CVE-2016-9904——An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon...
CVE-2016-9903——Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili...
CVE-2016-9902——The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o...
CVE-2016-9901——HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now