Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-01-03 CVE-2017-18322 Information Exposure vulnerability in Qualcomm products
Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016.
local
low complexity
qualcomm CWE-200
5.5
2019-01-03 CVE-2017-18321 Information Exposure vulnerability in Qualcomm products
Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.
local
low complexity
qualcomm CWE-200
5.5
2019-01-02 CVE-2018-7900 Information Exposure vulnerability in Huawei products
There is an information leak vulnerability in some Huawei HG products.
network
low complexity
huawei CWE-200
6.5
2018-12-30 CVE-2018-20609 Information Exposure vulnerability in Txjia Imcat 4.4
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.
network
low complexity
txjia CWE-200
5.3
2018-12-30 CVE-2018-20608 Information Exposure vulnerability in Txjia Imcat 4.4
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
network
low complexity
txjia CWE-200
7.5
2018-12-30 CVE-2018-20607 Information Exposure vulnerability in Txjia Imcat 4.4
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.
network
low complexity
txjia CWE-200
5.3
2018-12-30 CVE-2018-20606 Information Exposure vulnerability in Txjia Imcat 4.4
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
network
low complexity
txjia CWE-200
7.5
2018-12-30 CVE-2018-20602 Information Exposure vulnerability in Lfdycms LEI Feng TV CMS 3.8.6
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.
network
low complexity
lfdycms CWE-200
7.5
2018-12-28 CVE-2018-14986 Information Exposure vulnerability in Leagoo Z5C Firmware
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) containing an exported content provider named com.android.messaging.datamodel.MessagingContentProvider.
network
low complexity
leagoo CWE-200
7.5
2018-12-28 CVE-2018-14984 Information Exposure vulnerability in Leagoo Z5C Firmware
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) with an exported broadcast receiver app component named com.android.messaging.trackersender.TrackerSender.
network
low complexity
leagoo CWE-200
7.5