Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-12-27 CVE-2017-17864 Information Exposure vulnerability in multiple products
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
local
low complexity
linux debian CWE-200
3.3
2017-12-27 CVE-2017-1698 Information Exposure vulnerability in IBM Websphere Portal
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system.
network
low complexity
ibm CWE-200
5.3
2017-12-25 CVE-2017-13869 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-12-25 CVE-2017-13868 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-12-25 CVE-2017-13865 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-12-25 CVE-2017-13864 Information Exposure vulnerability in Apple Icloud and Itunes
An issue was discovered in certain Apple products.
network
high complexity
apple CWE-200
5.9
2017-12-22 CVE-2017-15328 Information Exposure vulnerability in Huawei Hg8245H Firmware
Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability.
network
low complexity
huawei CWE-200
7.5
2017-12-22 CVE-2017-15321 Information Exposure vulnerability in Huawei Fusionsphere Openstack V100R006C000Spc102(Nfv)
Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default.
network
high complexity
huawei CWE-200
3.7
2017-12-21 CVE-2017-17692 Information Exposure vulnerability in Samsung Internet Browser 5.4.02.3
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
network
low complexity
samsung CWE-200
7.5
2017-12-20 CVE-2017-5262 Information Exposure vulnerability in Cambiumnetworks products
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
low complexity
cambiumnetworks CWE-200
8.0