Vulnerabilities
Vulnerable Software
Lenovo:  >> Shareit  >> 3.0.18_ww  Security Vulnerabilities
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.
CVSS Score
6.1
EPSS Score
0.006
Published
2016-01-26
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.
CVSS Score
8.0
EPSS Score
0.006
Published
2016-01-26
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
CVSS Score
7.5
EPSS Score
0.002
Published
2014-03-03


Contact Us

Shodan ® - All rights reserved