Vulnerabilities > Lenovo > Shareit > High

DATE CVE VULNERABILITY TITLE RISK
2016-05-23 CVE-2016-4782 Improper Input Validation vulnerability in Lenovo Shareit 3.5.98Ww
Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent scheme URL attack."
network
low complexity
lenovo CWE-20
8.8
2016-01-26 CVE-2016-1491 Credentials Management vulnerability in Lenovo Shareit 2.5.1.1
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
low complexity
lenovo CWE-255
8.8
2016-01-26 CVE-2016-1489 7PK - Security Features vulnerability in Lenovo Shareit 2.5.1.1/3.0.18Ww
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.
high complexity
lenovo CWE-254
8.0