Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-08-17 CVE-2017-6778 Information Exposure vulnerability in Cisco Ultra Services Platform 21.0.V0.65839
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information.
network
low complexity
cisco CWE-200
6.5
2017-08-17 CVE-2017-6777 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3/2.3(2)
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information.
network
low complexity
cisco CWE-200
4.9
2017-08-17 CVE-2017-6772 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3(2)
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information.
network
low complexity
cisco CWE-200
4.3
2017-08-17 CVE-2017-6771 Information Exposure vulnerability in Cisco Ultra Services Framework 21.0.V0.65839
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information.
network
low complexity
cisco CWE-200
7.5
2017-08-16 CVE-2016-5858 Information Exposure vulnerability in Google Android
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.
local
high complexity
google CWE-200
4.7
2017-08-16 CVE-2016-5855 Information Exposure vulnerability in Google Android
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structure without checking if the source buffer is large enough.
local
high complexity
google CWE-200
4.7
2017-08-16 CVE-2016-5854 Information Exposure vulnerability in Google Android
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.
local
high complexity
google CWE-200
4.7
2017-08-16 CVE-2016-5347 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driver.
local
high complexity
google CWE-200
4.7
2017-08-15 CVE-2017-12855 Information Exposure vulnerability in XEN
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use.
local
low complexity
xen CWE-200
6.5
2017-08-14 CVE-2016-6029 Information Exposure vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.9