Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-07-20 CVE-2017-7058 Information Exposure vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
low complexity
apple CWE-200
2.4
2017-07-20 CVE-2017-7029 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-07-20 CVE-2017-7028 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-07-19 CVE-2016-6018 Information Exposure vulnerability in IBM Emptoris Contract Management
IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further attacks.
network
low complexity
ibm CWE-200
4.3
2017-07-19 CVE-2017-11448 Information Exposure vulnerability in Imagemagick
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
network
low complexity
imagemagick CWE-200
6.5
2017-07-19 CVE-2017-11435 Information Exposure vulnerability in Humaxdigital Hg100R Firmware 2.0.6
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console.
network
low complexity
humaxdigital CWE-200
critical
9.8
2017-07-19 CVE-2017-9245 Information Exposure vulnerability in Google News and Weather
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.
network
low complexity
google CWE-200
7.5
2017-07-17 CVE-2017-9933 Information Exposure vulnerability in Joomla Joomla!
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
network
low complexity
joomla CWE-200
7.5
2017-07-17 CVE-2017-9812 Information Exposure vulnerability in Kaspersky Anti-Virus for Linux Server 8.0.3.297
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.
network
low complexity
kaspersky CWE-200
7.5
2017-07-17 CVE-2017-7947 Information Exposure vulnerability in Netapp Clustered Data Ontap 8.3.2/9.0/9.1
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
network
low complexity
netapp CWE-200
6.5