Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-06-11 CVE-2017-9526 Information Exposure vulnerability in Gnupg Libgcrypt
In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key.
network
high complexity
gnupg CWE-200
5.9
2017-06-09 CVE-2017-2180 Information Exposure vulnerability in IPA Appgoat 3.0.0/3.0.1/3.0.2
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors.
network
low complexity
ipa CWE-200
4.3
2017-06-09 CVE-2017-2165 Information Exposure vulnerability in Groupsession 4.6.4
GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors.
network
low complexity
groupsession CWE-200
6.5
2017-06-09 CVE-2016-7832 Information Exposure vulnerability in Cybozu Dezie
Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to obtain an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.
network
low complexity
cybozu CWE-200
5.3
2017-06-09 CVE-2016-7814 Information Exposure vulnerability in Iodata Ts-Wrla Firmware and Ts-Wrlp Firmware
I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authentication credentials via unspecified vectors.
network
low complexity
iodata CWE-200
7.5
2017-06-08 CVE-2016-9736 Information Exposure vulnerability in IBM Websphere Application Server 8.0/8.5/9.0
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.
network
low complexity
ibm CWE-200
5.3
2017-06-08 CVE-2016-8987 Information Exposure vulnerability in IBM Maximo Asset Management 7.1/7.5/7.6
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
network
low complexity
ibm CWE-200
4.3
2017-06-08 CVE-2015-3634 Information Exposure vulnerability in Slideshow Project Slideshow
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
network
low complexity
slideshow-project CWE-200
7.5
2017-06-08 CVE-2016-5416 Information Exposure vulnerability in Redhat products
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.
network
low complexity
redhat CWE-200
7.5
2017-06-08 CVE-2016-4992 Information Exposure vulnerability in Redhat products
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.
network
low complexity
redhat CWE-200
7.5