Vulnerabilities > 7PK - Security Features

DATE CVE VULNERABILITY TITLE RISK
2019-04-22 CVE-2016-1585 7PK - Security Features vulnerability in Canonical Apparmor
In all versions of AppArmor mount rules are accidentally widened when compiled.
network
low complexity
canonical CWE-254
critical
9.8
2019-04-22 CVE-2014-1428 7PK - Security Features vulnerability in Canonical Metal AS a Service 1.9.0/1.9.1
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames.
network
low complexity
canonical CWE-254
5.3
2019-04-22 CVE-2011-3145 7PK - Security Features vulnerability in Mount.Ecrpytfs Private Project Mount.Ecrpytfs Private
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id.
network
low complexity
mount-ecrpytfs-private-project CWE-254
critical
9.8
2019-04-18 CVE-2016-10746 7PK - Security Features vulnerability in multiple products
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
network
low complexity
redhat debian CWE-254
7.5
2019-04-07 CVE-2019-10741 7PK - Security Features vulnerability in K-9 Mail Project K-9 Mail 5.600
K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages.
network
low complexity
k-9-mail-project CWE-254
4.3
2019-03-27 CVE-2017-2752 7PK - Security Features vulnerability in HP Tommy Hilfiger Th24/7
A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19.
low complexity
hp CWE-254
2.1
2019-03-27 CVE-2017-2748 7PK - Security Features vulnerability in HP Isaac Mizrahi Smartwatch
A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app.
network
low complexity
hp CWE-254
7.5
2019-01-11 CVE-2017-2411 7PK - Security Features vulnerability in Apple Iphone OS
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS.
network
high complexity
apple CWE-254
5.9
2019-01-11 CVE-2016-4642 7PK - Security Features vulnerability in Apple Iphone OS
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely.
network
high complexity
apple CWE-254
5.9
2018-08-28 CVE-2014-6050 7PK - Security Features vulnerability in PHPmyfaq
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
network
low complexity
phpmyfaq CWE-254
5.3