Vulnerabilities > 7PK - Security Features

DATE CVE VULNERABILITY TITLE RISK
2016-11-10 CVE-2016-7222 7PK - Security Features vulnerability in Microsoft Windows 10 and Windows Server 2016
Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to gain privileges via a crafted UNC pathname in a task, aka "Task Scheduler Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-254
7.8
2016-11-03 CVE-2016-4025 7PK - Security Features vulnerability in Avast products
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.
local
low complexity
avast CWE-254
5.5
2016-10-31 CVE-2016-7989 7PK - Security Features vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar.
network
low complexity
google CWE-254
7.5
2016-10-28 CVE-2016-4394 7PK - Security Features vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.
network
low complexity
hp CWE-254
6.5
2016-10-28 CVE-2016-9028 7PK - Security Features vulnerability in Citrix Netscaler Application Delivery Controller Firmware
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
network
low complexity
citrix CWE-254
8.8
2016-10-28 CVE-2016-8600 7PK - Security Features vulnerability in Dotcms 3.2.1
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
network
low complexity
dotcms CWE-254
7.5
2016-10-26 CVE-2016-8503 7PK - Security Features vulnerability in Yandex Browser 16.7.0.3342/16.7.1.20808/16.9.1.1131
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
network
low complexity
yandex CWE-254
7.3
2016-10-26 CVE-2016-8502 7PK - Security Features vulnerability in Yandex Browser 15.12.0.6151/15.12.1.6475/16.2.0.3539
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
network
low complexity
yandex CWE-254
7.3
2016-10-25 CVE-2016-5540 7PK - Security Features vulnerability in Oracle Micros Xstore Payment 1.0
Unspecified vulnerability in the Oracle Retail Xstore Payment component in Oracle Retail Applications 1.x allows local users to affect confidentiality and integrity via unknown vectors.
high complexity
oracle CWE-254
6.7
2016-10-25 CVE-2016-5511 7PK - Security Features vulnerability in Oracle Webcenter Sites 12.2.1.0.0/12.2.1.1.0/12.2.1.2.0
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0 allows remote attackers to affect integrity via unknown vectors.
network
low complexity
oracle CWE-254
4.3