Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-03-30 CVE-2017-1756 Information Exposure vulnerability in IBM Business Process Manager
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
3.3
2018-03-30 CVE-2017-1705 Information Exposure vulnerability in IBM Security Privileged Identity Manager 2.1.0
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments.
network
low complexity
ibm CWE-200
4.3
2018-03-30 CVE-2017-9681 Information Exposure vulnerability in Google Android
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls ioctl, it will print kernel address data.
network
low complexity
google CWE-200
6.5
2018-03-29 CVE-2016-6658 Information Exposure vulnerability in multiple products
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack.
network
low complexity
cloudfoundry pivotal-software CWE-200
critical
9.6
2018-03-29 CVE-2018-1191 Information Exposure vulnerability in Cloudfoundry Cf-Deployment and Garden-Runc-Release
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
network
low complexity
cloudfoundry CWE-200
8.8
2018-03-29 CVE-2014-5028 Information Exposure vulnerability in Reviewboard Review Board
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
network
low complexity
reviewboard CWE-200
6.5
2018-03-28 CVE-2018-6608 Information Exposure vulnerability in Opera Browser 51.0.2830.55
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
network
low complexity
opera CWE-200
4.3
2018-03-28 CVE-2018-7676 Information Exposure vulnerability in Netiq Identity Manager 4.5
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
network
high complexity
netiq CWE-200
5.9
2018-03-27 CVE-2017-7630 Information Exposure vulnerability in Qnap QTS 4.2.6/4.3.3
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
network
low complexity
qnap CWE-200
5.3
2018-03-27 CVE-2014-5132 Information Exposure vulnerability in Avolvesoftware Projectdox 8.1
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
network
low complexity
avolvesoftware CWE-200
4.3