2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6543A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS ...
CVE-2016-6542The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an...
CVE-2016-0708Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat...
CVE-2016-9604MEDIUM4.4It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '...
CVE-2016-10726The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ pa...
CVE-2016-5015Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-4466Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6541TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to var...
CVE-2016-6540Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data...
CVE-2016-6539The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever...
CVE-2016-6538The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache....
CVE-2016-10725In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to overr...
CVE-2016-10724Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (d...
CVE-2016-10545Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2016-10522rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not valida...
CVE-2016-10723An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the...
CVE-2016-1000025Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10542. Reason: This candidate is a reservation ...
CVE-2016-1000023Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation ...
CVE-2016-1000013Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10531. Reason: This candidate is a reservation ...
CVE-2016-9905A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af...
CVE-2016-9904An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon...
CVE-2016-9903Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili...
CVE-2016-9902The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o...
CVE-2016-9901HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b...
CVE-2016-9900External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now