Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-07-04 CVE-2017-6706 Information Exposure vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information.
local
low complexity
cisco CWE-200
5.1
2017-07-04 CVE-2017-6705 Information Exposure vulnerability in Cisco Prime Collaboration Provisioning 12.1
A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitive information.
local
low complexity
cisco CWE-200
5.5
2017-07-03 CVE-2016-5045 Information Exposure vulnerability in Netapp Oncommand System Manager 8.3/8.3.1/8.3.2
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.
network
high complexity
netapp CWE-200
8.1
2017-07-02 CVE-2017-0377 Information Exposure vulnerability in Torproject TOR
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.
network
low complexity
torproject CWE-200
7.5
2017-06-30 CVE-2017-8443 Information Exposure vulnerability in Elastic Kibana
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen.
network
low complexity
elastic CWE-200
6.5
2017-06-30 CVE-2017-7899 Information Exposure vulnerability in Rockwellautomation products
An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions.
network
low complexity
rockwellautomation CWE-200
critical
9.8
2017-06-30 CVE-2017-6046 Information Exposure vulnerability in Sierra Wireless products
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11.
network
low complexity
sierra-wireless CWE-200
7.5
2017-06-30 CVE-2017-6040 Information Exposure vulnerability in Belden Hirschmann Gecko Lite Managed Switch Firmware
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions.
network
low complexity
belden-hirschmann CWE-200
5.3
2017-06-29 CVE-2017-10679 Information Exposure vulnerability in Piwigo
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album.
network
low complexity
piwigo CWE-200
7.5
2017-06-29 CVE-2017-5529 Information Exposure vulnerability in Tibco products
JasperReports library components contain an information disclosure vulnerability.
network
low complexity
tibco CWE-200
6.5