Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-09-21 CVE-2013-7203 Information Exposure vulnerability in Gitolite
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
local
low complexity
gitolite CWE-200
5.5
2018-09-21 CVE-2018-8023 Information Exposure vulnerability in Apache Mesos
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT).
network
high complexity
apache CWE-200
5.9
2018-09-21 CVE-2018-1685 Information Exposure vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system.
local
low complexity
ibm CWE-200
5.5
2018-09-20 CVE-2018-1800 Information Exposure vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring.
local
high complexity
ibm CWE-200
4.7
2018-09-19 CVE-2018-3831 Information Exposure vulnerability in Elastic Elasticsearch
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API.
network
low complexity
elastic CWE-200
8.8
2018-09-18 CVE-2018-16671 Information Exposure vulnerability in Circontrol Circarlife Scada
An issue was discovered in CIRCONTROL CirCarLife before 4.3.
network
low complexity
circontrol CWE-200
5.3
2018-09-18 CVE-2018-11275 Information Exposure vulnerability in Google Android
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if size is not divisible by block size, information leak occurs.
local
low complexity
google CWE-200
5.5
2018-09-18 CVE-2018-14642 Information Exposure vulnerability in Redhat Jboss Enterprise Application Platform and Undertow
An information leak vulnerability was found in Undertow.
network
low complexity
redhat CWE-200
5.3
2018-09-18 CVE-2018-16959 Information Exposure vulnerability in Oracle Webcenter Interaction 10.3.3
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3.
network
low complexity
oracle CWE-200
5.3
2018-09-17 CVE-2017-14443 Information Exposure vulnerability in Insteon HUB 2245-222 Firmware 1012
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-200
6.5