Vulnerabilities > 7PK - Security Features

DATE CVE VULNERABILITY TITLE RISK
2016-04-18 CVE-2016-1657 7PK - Security Features vulnerability in multiple products
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
network
low complexity
debian novell opensuse google CWE-254
4.3
2016-04-12 CVE-2016-2118 7PK - Security Features vulnerability in multiple products
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "BADLOCK."
network
high complexity
samba canonical debian CWE-254
7.5
2016-04-12 CVE-2016-0161 7PK - Security Features vulnerability in Microsoft Edge
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.
network
low complexity
microsoft CWE-254
6.5
2016-04-12 CVE-2016-0158 7PK - Security Features vulnerability in Microsoft Edge
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0161.
network
low complexity
microsoft CWE-254
6.5
2016-04-12 CVE-2016-0128 7PK - Security Features vulnerability in Microsoft products
The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "Windows SAM and LSAD Downgrade Vulnerability" or "BADLOCK."
network
high complexity
microsoft CWE-254
6.8
2016-04-12 CVE-2016-3168 7PK - Security Features vulnerability in multiple products
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
network
high complexity
drupal debian CWE-254
6.4
2016-04-12 CVE-2016-3163 7PK - Security Features vulnerability in multiple products
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
network
low complexity
debian drupal CWE-254
7.5
2016-04-12 CVE-2015-8108 7PK - Security Features vulnerability in Lenovo EMC Firmware 4.1.204.33661
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.
network
low complexity
lenovo CWE-254
5.3
2016-04-11 CVE-2015-7330 7PK - Security Features vulnerability in Puppet Enterprise 2015.3.0
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol.
network
low complexity
puppet CWE-254
8.8
2016-04-11 CVE-2015-5303 7PK - Security Features vulnerability in Openstack Tripleo Heat Templates
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
network
low complexity
openstack CWE-254
7.5