Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-10-26 CVE-2018-11846 Information Exposure vulnerability in Qualcomm products
The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 845, SD 850
local
high complexity
qualcomm CWE-200
4.7
2018-10-26 CVE-2018-18655 Information Exposure vulnerability in Prayer Project Prayer
Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
network
low complexity
prayer-project CWE-200
4.3
2018-10-24 CVE-2018-18566 Information Exposure vulnerability in Polycom Unified Communications Software
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
network
low complexity
polycom CWE-200
5.3
2018-10-23 CVE-2018-18467 Information Exposure vulnerability in Conversations 2.3.4
An issue was discovered in Daniel Gultsch Conversations 2.3.4.
network
low complexity
conversations CWE-200
7.5
2018-10-23 CVE-2017-18300 Information Exposure vulnerability in Qualcomm products
Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SDA660.
local
low complexity
qualcomm CWE-200
5.5
2018-10-19 CVE-2018-18428 Information Exposure vulnerability in Tp-Link Tl-Sc3130 Firmware 1.6.18P12121101
TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.
network
low complexity
tp-link CWE-200
7.5
2018-10-19 CVE-2018-12673 Information Exposure vulnerability in Sv3C H.264 POE IP Camera Firmware V2.3.4.2103S50Ntdb20170508B/V2.3.4.2103S50Ntdb20170823B
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireless network, and local area network information.
network
low complexity
sv3c CWE-200
7.5
2018-10-19 CVE-2018-12671 Information Exposure vulnerability in Sv3C H.264 POE IP Camera Firmware V2.3.4.2103S50Ntdb20170508B/V2.3.4.2103S50Ntdb20170823B
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set within the camera.
network
low complexity
sv3c CWE-200
critical
9.8
2018-10-19 CVE-2018-18390 Information Exposure vulnerability in Moxa Thingspro 2.1
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
network
low complexity
moxa CWE-200
7.5
2018-10-18 CVE-2018-15765 Information Exposure vulnerability in Dell EMC Secure Remote Services
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability.
local
low complexity
dell CWE-200
5.5