Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-11-13 CVE-2018-6260 Information Exposure vulnerability in Nvidia GPU Driver
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters.
local
low complexity
nvidia CWE-200
5.5
2018-11-13 CVE-2018-15771 Information Exposure vulnerability in EMC Recoverpoint and Recoverpoint for Virtual Machines
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability.
local
low complexity
emc CWE-200
5.5
2018-11-13 CVE-2018-18591 Information Exposure vulnerability in Microfocus Service Manager
A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51.
network
low complexity
microfocus CWE-200
6.5
2018-11-13 CVE-2018-19246 Information Exposure vulnerability in PHP-Proxy 5.1.0
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used.
network
low complexity
php-proxy CWE-200
7.5
2018-11-12 CVE-2018-19226 Information Exposure vulnerability in Laobancms 2.0
An issue was discovered in LAOBANCMS 2.0.
network
low complexity
laobancms CWE-200
5.3
2018-11-12 CVE-2018-19205 Information Exposure vulnerability in Roundcube Webmail
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688.
network
low complexity
roundcube CWE-200
7.5
2018-11-12 CVE-2018-19194 Information Exposure vulnerability in Xiaocms 20141229
An issue was discovered in XiaoCms 20141229.
network
low complexity
xiaocms CWE-200
5.3
2018-11-10 CVE-2018-19148 Information Exposure vulnerability in Caddyserver Caddy
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames.
network
high complexity
caddyserver CWE-200
3.7
2018-11-09 CVE-2018-19133 Information Exposure vulnerability in Flarum 0.1.0
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.
network
low complexity
flarum CWE-200
5.3
2018-11-09 CVE-2018-1857 Information Exposure vulnerability in IBM DB2 11.1
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see.
network
low complexity
ibm CWE-200
6.5