Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-07-25 CVE-2015-3171 Information Exposure vulnerability in SOS Project SOS 3.2
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
local
low complexity
sos-project CWE-200
5.5
2017-07-25 CVE-2017-8035 Information Exposure vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268.
network
low complexity
cloudfoundry CWE-200
7.5
2017-07-24 CVE-2017-9554 Information Exposure vulnerability in Synology Diskstation Manager
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
network
low complexity
synology CWE-200
5.3
2017-07-24 CVE-2017-11327 Information Exposure vulnerability in Tilde CMS Project Tilde CMS 1.0.1
An issue was discovered in Tilde CMS 1.0.1.
network
low complexity
tilde-cms-project CWE-200
6.5
2017-07-24 CVE-2017-11325 Information Exposure vulnerability in Tilde CMS Project Tilde CMS 1.0.1
An issue was discovered in Tilde CMS 1.0.1.
network
low complexity
tilde-cms-project CWE-200
7.5
2017-07-21 CVE-2017-1381 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served.
local
low complexity
ibm CWE-200
3.3
2017-07-21 CVE-2017-1374 Information Exposure vulnerability in IBM Tririga Application Platform
Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system.
network
low complexity
ibm CWE-200
6.5
2017-07-21 CVE-2015-3198 Information Exposure vulnerability in Redhat Jboss Wildfly Application Server 9.0.0
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.
network
low complexity
redhat CWE-200
7.5
2017-07-21 CVE-2015-1323 Information Exposure vulnerability in Canonical Ubuntu Linux
The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ubuntu 14.04 LTS, before 0.43+bzr805-0ubuntu10 as packaged in Ubuntu 12.04 LTS allows local users to obtain sensitive information, or access files with root permissions.
local
low complexity
canonical CWE-200
5.5
2017-07-20 CVE-2017-11502 Information Exposure vulnerability in Cisco Dpc3928Ad Docsis Wireless Router Firmware
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
network
low complexity
cisco CWE-200
critical
9.8