Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-10-18 CVE-2018-18487 Information Exposure vulnerability in Gxlcms 2.0
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.
network
low complexity
gxlcms CWE-200
7.5
2018-10-18 CVE-2018-12374 Information Exposure vulnerability in multiple products
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field.
network
low complexity
mozilla redhat debian canonical CWE-200
4.3
2018-10-18 CVE-2018-12373 Information Exposure vulnerability in multiple products
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward.
network
low complexity
mozilla redhat debian canonical CWE-200
6.5
2018-10-18 CVE-2018-12372 Information Exposure vulnerability in multiple products
Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward.
network
low complexity
mozilla redhat debian canonical CWE-200
6.5
2018-10-18 CVE-2018-12365 Information Exposure vulnerability in multiple products
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction.
network
low complexity
redhat debian canonical mozilla CWE-200
6.5
2018-10-18 CVE-2018-12358 Information Exposure vulnerability in multiple products
Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque.
network
low complexity
mozilla canonical CWE-200
4.3
2018-10-17 CVE-2018-14597 Information Exposure vulnerability in Broadcom products
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.
network
low complexity
broadcom CWE-200
5.3
2018-10-16 CVE-2018-18376 Information Exposure vulnerability in Orange Airbox Firmware Y858Fl01.1604
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
network
low complexity
orange CWE-200
7.5
2018-10-15 CVE-2018-18073 Information Exposure vulnerability in multiple products
Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
local
low complexity
artifex debian canonical redhat CWE-200
6.3
2018-10-14 CVE-2018-18289 Information Exposure vulnerability in Mesilat Zabbix
The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files.
network
low complexity
mesilat CWE-200
7.5