Vulnerabilities > 7PK - Security Features

DATE CVE VULNERABILITY TITLE RISK
2017-04-10 CVE-2016-5052 7PK - Security Features vulnerability in Osram Lightify Home 1.6.1
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
network
low complexity
osram CWE-254
7.5
2017-04-02 CVE-2016-8768 7PK - Security Features vulnerability in Huawei products
Huawei Honor 6, Honor 6 Plus, Honor 7 phones with software versions earlier than 6.9.16 could allow attackers to disable the PXN defense mechanism by invoking related drive code to crash the system or escalate privilege.
local
low complexity
huawei CWE-254
7.8
2017-03-30 CVE-2016-7541 7PK - Security Features vulnerability in Fortinet Fortios
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode.
network
high complexity
fortinet CWE-254
5.9
2017-03-28 CVE-2016-9470 7PK - Security Features vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download.
network
low complexity
revive-adserver CWE-254
critical
9.0
2017-03-24 CVE-2016-7797 7PK - Security Features vulnerability in multiple products
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
7.5
2017-03-14 CVE-2015-8990 7PK - Security Features vulnerability in Mcafee Advanced Threat Defense
Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.
network
low complexity
mcafee CWE-254
7.5
2017-03-14 CVE-2015-8986 7PK - Security Features vulnerability in Mcafee Advanced Threat Defense 3.4/3.4.2.32
Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resulting in failure to detect a malware file (false-negative) via specially crafted malware.
local
low complexity
mcafee CWE-254
5.5
2017-03-08 CVE-2016-5933 7PK - Security Features vulnerability in IBM Tivoli Monitoring
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass.
network
low complexity
ibm CWE-254
4.6
2017-03-01 CVE-2016-8508 7PK - Security Features vulnerability in Yandex Browser
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
network
low complexity
yandex CWE-254
6.5
2017-02-20 CVE-2016-7638 7PK - Security Features vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
low complexity
apple CWE-254
4.6