Vulnerabilities > Information Exposure
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-12-04 | CVE-2017-12079 | Information Exposure vulnerability in Synology Photo Station Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field. | 7.5 |
2017-12-04 | CVE-2017-17104 | Information Exposure vulnerability in Fiyo CMS 2.0.7 Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name']. | 7.5 |
2017-12-01 | CVE-2017-13664 | Information Exposure vulnerability in Ismartalarm Cubeone Firmware Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file. | 9.8 |
2017-11-30 | CVE-2017-3764 | Information Exposure vulnerability in Lenovo Xclarity Administrator A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. | 5.3 |
2017-11-30 | CVE-2017-12365 | Information Exposure vulnerability in Cisco Webex Meeting Center T32.6 A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. | 4.3 |
2017-11-30 | CVE-2017-12354 | Information Exposure vulnerability in Cisco Secure Access Control System 5.8(0.32) A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. | 5.3 |
2017-11-28 | CVE-2017-17046 | Information Exposure vulnerability in XEN An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled. | 6.5 |
2017-11-28 | CVE-2016-10702 | Information Exposure vulnerability in Pebble Firmware 4.3 Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by modifying a UUID value within the header of a crafted application binary. | 6.1 |
2017-11-27 | CVE-2017-1570 | Information Exposure vulnerability in IBM products IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. | 4.3 |
2017-11-27 | CVE-2017-1484 | Information Exposure vulnerability in IBM Websphere Commerce IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. | 4.3 |