2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3109 | — | — | 28.2% | Apr 21, 2017 | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. |
| CVE-2016-3067 | — | — | 2.0% | Apr 21, 2017 | Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain pr... |
| CVE-2016-2433 | — | — | 0.7% | Apr 21, 2017 | The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to... |
| CVE-2016-2347 | — | — | 3.2% | Apr 21, 2017 | Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote atta... |
| CVE-2016-1561 | — | — | 74.3% | Apr 21, 2017 | ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic... |
| CVE-2016-1560 | — | — | 72.3% | Apr 21, 2017 | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and... |
| CVE-2016-1520 | — | — | 2.2% | Apr 21, 2017 | The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m... |
| CVE-2016-1519 | — | — | 1.0% | Apr 21, 2017 | The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate... |
| CVE-2016-1518 | — | — | 1.7% | Apr 21, 2017 | The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP ph... |
| CVE-2016-1221 | — | — | 0.6% | Apr 21, 2017 | Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att... |
| CVE-2016-1210 | — | — | 0.6% | Apr 21, 2017 | The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allo... |
| CVE-2016-1198 | — | — | 0.8% | Apr 21, 2017 | Photopt for Android before 2.0.1 does not verify SSL certificates. |
| CVE-2016-1187 | — | — | 1.2% | Apr 21, 2017 | Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates. |
| CVE-2016-1186 | — | — | 0.9% | Apr 21, 2017 | Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates. |
| CVE-2016-6519 | — | — | 1.3% | Apr 21, 2017 | Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authent... |
| CVE-2016-1559 | — | — | 3.3% | Apr 21, 2017 | D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver... |
| CVE-2016-1558 | — | — | 9.1% | Apr 21, 2017 | Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ... |
| CVE-2016-1557 | — | — | 2.8% | Apr 21, 2017 | Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwo... |
| CVE-2016-1556 | — | — | 3.5% | Apr 21, 2017 | Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND93... |
| CVE-2016-10091 | — | — | 2.8% | Apr 21, 2017 | Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a n... |
| CVE-2016-0721 | — | — | 2.3% | Apr 21, 2017 | Session fixation vulnerability in pcsd in pcs before 0.9.157. |
| CVE-2016-0720 | — | — | 1.4% | Apr 21, 2017 | Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. |
| CVE-2016-4846 | — | — | 1.5% | Apr 21, 2017 | Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2. |
| CVE-2016-4841 | — | — | 1.5% | Apr 21, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers. |
| CVE-2016-4832 | — | — | 0.9% | Apr 21, 2017 | WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now