Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-11-06 CVE-2018-9489 Information Exposure vulnerability in Google Android
When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network information.
network
low complexity
google CWE-200
7.5
2018-11-06 CVE-2018-1606 Information Exposure vulnerability in IBM products
IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow an authenticated user to obtain sensitive information from an error message that could be used in further attacks against the system.
network
low complexity
ibm CWE-200
4.3
2018-11-05 CVE-2018-17907 Information Exposure vulnerability in Omron Cx-Supervisor
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
local
low complexity
omron CWE-200
3.3
2018-11-02 CVE-2018-16849 Information Exposure vulnerability in Redhat Openstack-Mistral 7.0.0
A flaw was found in openstack-mistral.
network
low complexity
redhat CWE-200
7.5
2018-11-02 CVE-2018-1878 Information Exposure vulnerability in IBM Robotic Process Automation With Automation Anywhere 11
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system.
network
low complexity
ibm CWE-200
5.3
2018-11-01 CVE-2018-3947 Information Exposure vulnerability in Yitechnology YI Home and YI Home Camera Firmware
An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D.
network
high complexity
yitechnology CWE-200
8.1
2018-11-01 CVE-2018-3928 Information Exposure vulnerability in Yitechnology YI Home Camera Firmware 1.8.7.0D
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D.
network
low complexity
yitechnology CWE-200
7.5
2018-10-31 CVE-2018-13281 Information Exposure vulnerability in Synology Diskstation Manager, Skynas and Vs960Hd
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
network
low complexity
synology CWE-200
4.3
2018-10-29 CVE-2018-1380 Information Exposure vulnerability in IBM Infosphere Master Data Management 11.4/11.5/11.6
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information.
network
low complexity
ibm CWE-200
4.9
2018-10-29 CVE-2018-18778 Information Exposure vulnerability in Acme Mini-Httpd
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
network
low complexity
acme CWE-200
6.5