Vulnerabilities > Information Exposure
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-12-26 | CVE-2018-20478 | Information Exposure vulnerability in S-Cms 1.0 An issue was discovered in S-CMS 1.0. | 7.5 |
2018-12-24 | CVE-2018-8919 | Information Exposure vulnerability in Synology Diskstation Manager Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors. | 9.8 |
2018-12-23 | CVE-2018-20371 | Information Exposure vulnerability in Photorange Photo Vault Project Photorange Photo Vault 1.2 PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on. | 9.8 |
2018-12-20 | CVE-2018-18441 | Information Exposure vulnerability in multiple products D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. | 7.5 |
2018-12-20 | CVE-2018-17244 | Information Exposure vulnerability in Elastic Elasticsearch 6.4.0/6.4.1/6.4.2 Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. | 6.5 |
2018-12-20 | CVE-2018-20307 | Information Exposure vulnerability in Pulsesecure Virtual Traffic Manager 10.4/17.2/9.9 Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation. | 4.3 |
2018-12-19 | CVE-2018-16883 | Information Exposure vulnerability in Fedoraproject Sssd sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. | 5.5 |
2018-12-18 | CVE-2017-15031 | Information Exposure vulnerability in ARM Arm-Trusted-Firmware In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information. | 7.5 |
2018-12-17 | CVE-2018-7812 | Information Exposure vulnerability in Schneider-Electric products An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not. | 7.5 |
2018-12-17 | CVE-2018-19976 | Information Exposure vulnerability in Virustotal Yara 3.8.1 In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. | 5.5 |