Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-10-17 CVE-2018-14597 Information Exposure vulnerability in Broadcom products
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.
network
low complexity
broadcom CWE-200
5.3
2018-10-16 CVE-2018-18376 Information Exposure vulnerability in Orange Airbox Firmware Y858Fl01.1604
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
network
low complexity
orange CWE-200
7.5
2018-10-15 CVE-2018-18073 Information Exposure vulnerability in multiple products
Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
local
low complexity
artifex debian canonical redhat CWE-200
6.3
2018-10-14 CVE-2018-18289 Information Exposure vulnerability in Mesilat Zabbix
The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files.
network
low complexity
mesilat CWE-200
7.5
2018-10-14 CVE-2018-18287 Information Exposure vulnerability in Asus Rt-Ac58U Firmware 3.0.0.4.380.6516
On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page.
network
low complexity
asus CWE-200
5.3
2018-10-12 CVE-2018-8890 Information Exposure vulnerability in Blackberry Unified Endpoint Manager 12.8.0/12.8.1
An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user's session and perform administrative actions in the context of the user.
network
low complexity
blackberry CWE-200
7.5
2018-10-12 CVE-2018-1838 Information Exposure vulnerability in IBM Websphere Application Server 8.5.0.0/9.0.0.0
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords.
network
low complexity
ibm CWE-200
6.5
2018-10-11 CVE-2018-1708 Information Exposure vulnerability in IBM Platform Symphony and Specturm Symphony
IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI.
network
low complexity
ibm CWE-200
6.5
2018-10-10 CVE-2018-12161 Information Exposure vulnerability in Intel Raid web Console 3.0
Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose information via network access.
network
low complexity
intel CWE-200
6.5
2018-10-10 CVE-2018-12158 Information Exposure vulnerability in Intel Next Unit of Computing Firmware
Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially trigger a denial of service or information disclosure via local access.
local
low complexity
intel CWE-200
6.0