Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-11-20 CVE-2017-15110 Information Exposure vulnerability in Moodle
In Moodle 3.x, students can find out email addresses of other students in the same course.
network
low complexity
moodle CWE-200
4.3
2017-11-20 CVE-2017-16894 Information Exposure vulnerability in Laravel
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI.
network
low complexity
laravel CWE-200
7.5
2017-11-17 CVE-2017-13702 Information Exposure vulnerability in Moxa Eds-G512E Firmware 5.1
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices.
network
low complexity
moxa CWE-200
5.3
2017-11-17 CVE-2017-10888 Information Exposure vulnerability in Bookwalker Book Walker 1.2.5/1.2.9
BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access local files via unspecified vectors.
local
low complexity
bookwalker CWE-200
5.5
2017-11-17 CVE-2017-1000226 Information Exposure vulnerability in Fullworks Stop User Enumeration 1.3.8
Stop User Enumeration 1.3.8 allows user enumeration via the REST API
network
low complexity
fullworks CWE-200
5.3
2017-11-17 CVE-2017-1000234 Information Exposure vulnerability in I-Librarian I Librarian
I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simply by navigating through the "dir" parameter
network
low complexity
i-librarian CWE-200
5.3
2017-11-17 CVE-2017-1000199 Information Exposure vulnerability in Tcmu-Runner Project Tcmu-Runner
tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.
network
low complexity
tcmu-runner-project CWE-200
7.5
2017-11-17 CVE-2017-15517 Information Exposure vulnerability in Netapp Altavault OST Plug-In
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors.
local
low complexity
netapp CWE-200
5.5
2017-11-16 CVE-2017-0851 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libhevc).
network
low complexity
google CWE-200
5.3
2017-11-16 CVE-2017-0850 Information Exposure vulnerability in Google Android 7.0/7.1.1/7.1.2
An information disclosure vulnerability in the Android media framework (libstagefright).
network
low complexity
google CWE-200
5.3