Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-10-31 CVE-2017-10944 Information Exposure vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-200
6.5
2017-10-31 CVE-2017-10943 Information Exposure vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-200
6.5
2017-10-31 CVE-2017-10942 Information Exposure vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-200
6.5
2017-10-31 CVE-2017-3935 Information Exposure vulnerability in Mcafee Network Data Loss Prevention 9.3.0
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the intended content type.
network
low complexity
mcafee CWE-200
7.5
2017-10-31 CVE-2017-3934 Information Exposure vulnerability in Mcafee Network Data Loss Prevention 9.3.0
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.
network
high complexity
mcafee CWE-200
5.9
2017-10-30 CVE-2017-15597 Information Exposure vulnerability in XEN 4.8.0/4.9.0
An issue was discovered in Xen through 4.9.x.
network
low complexity
xen CWE-200
critical
9.1
2017-10-30 CVE-2014-3526 Information Exposure vulnerability in Apache Wicket
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
network
low complexity
apache CWE-200
7.5
2017-10-27 CVE-2017-15937 Information Exposure vulnerability in Artica Pandora FMS 7.0
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition.
network
low complexity
artica CWE-200
6.5
2017-10-27 CVE-2017-5117 Information Exposure vulnerability in multiple products
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google debian CWE-200
6.5
2017-10-27 CVE-2017-5096 Information Exposure vulnerability in Google Chrome
Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.
network
low complexity
google CWE-200
4.3