Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-07-11 CVE-2018-8305 Information Exposure vulnerability in Microsoft Windows Calendar, Windows Mail and Windows People
An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulnerability." This affects Mail, Calendar, and People in Windows 8.1 App Store.
network
low complexity
microsoft CWE-200
6.5
2018-07-11 CVE-2018-8297 Information Exposure vulnerability in Microsoft Edge
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge.
network
low complexity
microsoft CWE-200
4.3
2018-07-11 CVE-2018-8289 Information Exposure vulnerability in Microsoft Edge
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge.
network
low complexity
microsoft CWE-200
4.3
2018-07-10 CVE-2018-3652 Information Exposure vulnerability in Intel products
Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.
low complexity
intel CWE-200
7.6
2018-07-10 CVE-2018-3619 Information Exposure vulnerability in Intel products
Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access.
low complexity
intel CWE-200
4.6
2018-07-10 CVE-2018-10890 Information Exposure vulnerability in Moodle
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13.
network
low complexity
moodle CWE-200
5.3
2018-07-10 CVE-2018-1423 Information Exposure vulnerability in IBM products
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system.
network
low complexity
ibm CWE-200
6.5
2018-07-10 CVE-2018-1337 Information Exposure vulnerability in Apache Directory Ldap API 1.0.0
In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
network
low complexity
apache CWE-200
critical
9.8
2018-07-09 CVE-2018-4993 Information Exposure vulnerability in Adobe Acrobat DC
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability.
network
low complexity
adobe CWE-200
7.5
2018-07-09 CVE-2018-4965 Information Exposure vulnerability in Adobe Acrobat DC and Acrobat Reader DC
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Memory Corruption vulnerability.
network
low complexity
adobe CWE-200
7.5