Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-11-14 CVE-2018-17468 Information Exposure vulnerability in multiple products
Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obtain cross origin URLs via a crafted HTML page.
network
low complexity
google redhat debian CWE-200
6.5
2018-11-14 CVE-2018-3621 Information Exposure vulnerability in Intel Driver&Support Assistant
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
low complexity
intel CWE-200
6.5
2018-11-14 CVE-2018-8565 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
local
low complexity
microsoft CWE-200
5.5
2018-11-14 CVE-2018-8558 Information Exposure vulnerability in Microsoft Office and Office 365 Proplus
An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
network
low complexity
microsoft CWE-200
6.5
2018-11-14 CVE-2018-8454 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, aka "Windows Audio Service Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
local
low complexity
microsoft CWE-200
5.5
2018-11-13 CVE-2018-6260 Information Exposure vulnerability in Nvidia GPU Driver
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters.
local
low complexity
nvidia CWE-200
5.5
2018-11-13 CVE-2018-15771 Information Exposure vulnerability in EMC Recoverpoint and Recoverpoint for Virtual Machines
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability.
local
low complexity
emc CWE-200
5.5
2018-11-13 CVE-2018-18591 Information Exposure vulnerability in Microfocus Service Manager
A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51.
network
low complexity
microfocus CWE-200
6.5
2018-11-13 CVE-2018-19246 Information Exposure vulnerability in PHP-Proxy 5.1.0
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used.
network
low complexity
php-proxy CWE-200
7.5
2018-11-12 CVE-2018-19226 Information Exposure vulnerability in Laobancms 2.0
An issue was discovered in LAOBANCMS 2.0.
network
low complexity
laobancms CWE-200
5.3