Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-03-25 CVE-2018-9014 Information Exposure vulnerability in Dsmall Project Dsmall 20180320
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.
network
low complexity
dsmall-project CWE-200
7.5
2018-03-23 CVE-2017-1524 Information Exposure vulnerability in IBM products
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks.
network
low complexity
ibm CWE-200
4.3
2018-03-22 CVE-2016-9711 Information Exposure vulnerability in IBM Cognos Analytics 11.0.0
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system.
network
low complexity
ibm CWE-200
5.3
2018-03-20 CVE-2018-3626 Information Exposure vulnerability in Intel SGX SDK
Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
local
high complexity
intel CWE-200
4.7
2018-03-20 CVE-2018-1322 Information Exposure vulnerability in Apache Syncope
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
network
low complexity
apache CWE-200
4.9
2018-03-20 CVE-2017-17319 Information Exposure vulnerability in Huawei P9 Firmware
Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability.
local
low complexity
huawei CWE-200
5.5
2018-03-20 CVE-2018-1000135 Information Exposure vulnerability in multiple products
GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN.
network
low complexity
gnome canonical CWE-200
7.5
2018-03-19 CVE-2014-5450 Information Exposure vulnerability in Zarafa Collaboration Platform 4.1
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.
local
low complexity
zarafa CWE-200
5.5
2018-03-19 CVE-2014-4024 Information Exposure vulnerability in F5 products
SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accelerator cards, might allow remote attackers to have unspecified impact via a timing side-channel attack.
network
high complexity
f5 CWE-200
5.9
2018-03-18 CVE-2018-8770 Information Exposure vulnerability in Cobub Razor 0.8.0
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php, fixtures/Controller_fixt.php, fixtures/Controller_fixt2.php, fixtures/view_fixt2.php, libs/ipTest.php, or models/commonDbfix.php in tests/.
network
low complexity
cobub CWE-200
5.3