Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-06-17 CVE-2018-12329 Information Exposure vulnerability in Ecos Secure Boot Stick Firmware 5.6.5
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.
network
high complexity
ecos CWE-200
5.9
2018-06-16 CVE-2018-5751 Information Exposure vulnerability in Open-Xchange Appsuite
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the "groups" and "users" APIs.
network
low complexity
open-xchange CWE-200
6.5
2018-06-15 CVE-2018-12481 Information Exposure vulnerability in the Olive Tree FTP Server Project the Olive Tree FTP Server 1.32
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboard module.
network
low complexity
the-olive-tree-ftp-server-project CWE-200
critical
9.8
2018-06-15 CVE-2018-6672 Information Exposure vulnerability in Mcafee Epolicy Orchestrator
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.
network
low complexity
mcafee CWE-200
6.5
2018-06-15 CVE-2018-12440 Information Exposure vulnerability in Google Boringssl 20180614
BoringSSL through 2018-06-14 allows a memory-cache side-channel attack on DSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
local
high complexity
google CWE-200
4.7
2018-06-15 CVE-2018-12439 Information Exposure vulnerability in Matrixssl
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
local
high complexity
matrixssl CWE-200
4.7
2018-06-15 CVE-2018-12437 Information Exposure vulnerability in multiple products
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
high complexity
libtom linaro CWE-200
4.9
2018-06-15 CVE-2018-12436 Information Exposure vulnerability in Wolfssl
wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
local
high complexity
wolfssl CWE-200
4.7
2018-06-15 CVE-2018-12435 Information Exposure vulnerability in Botan Project Botan 2.5.0/2.6.0/2.7.0
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, related to dsa/dsa.cpp, ec_group/ec_group.cpp, and ecdsa/ecdsa.cpp.
local
high complexity
botan-project CWE-200
5.9
2018-06-15 CVE-2018-12434 Information Exposure vulnerability in Openbsd Libressl
LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
local
high complexity
openbsd CWE-200
4.7