Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-02-12 CVE-2017-13239 Information Exposure vulnerability in Google Android 8.0
A information disclosure vulnerability in the Android framework (ui framework).
network
low complexity
google CWE-200
7.5
2018-02-12 CVE-2017-13238 Information Exposure vulnerability in Google Android
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device.
high complexity
google CWE-200
4.2
2018-02-12 CVE-2018-6881 Information Exposure vulnerability in multiple products
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
network
low complexity
phome dedecms CWE-200
5.3
2018-02-09 CVE-2018-1052 Information Exposure vulnerability in Postgresql 10.0/10.1
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
network
low complexity
postgresql CWE-200
6.5
2018-02-08 CVE-2012-3331 Information Exposure vulnerability in IBM Sametime
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF.
network
low complexity
ibm CWE-200
5.3
2018-02-08 CVE-2018-6846 Information Exposure vulnerability in Zblogcn Z-Blogphp 1.5.1
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.
network
low complexity
zblogcn CWE-200
5.3
2018-02-07 CVE-2018-1388 Information Exposure vulnerability in IBM Websphere MQ
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding.
network
low complexity
ibm CWE-200
7.5
2018-02-07 CVE-2017-1785 Information Exposure vulnerability in IBM API Connect
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information.
network
low complexity
ibm CWE-200
4.3
2018-02-07 CVE-2018-6806 Information Exposure vulnerability in Marked 2 Project Marked 2
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL.
network
low complexity
marked-2-project CWE-200
6.5
2018-02-07 CVE-2018-6790 Information Exposure vulnerability in KDE Plasma-Workspace
An issue was discovered in KDE Plasma Workspace before 5.12.0.
network
low complexity
kde CWE-200
5.3