Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-04-02 CVE-2017-2400 Information Exposure vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-200
5.3
2017-04-02 CVE-2017-2397 Information Exposure vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
low complexity
apple CWE-200
2.4
2017-04-02 CVE-2017-2385 Information Exposure vulnerability in Apple Safari
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
5.5
2017-04-02 CVE-2017-2384 Information Exposure vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
3.3
2017-04-02 CVE-2017-2382 Information Exposure vulnerability in Apple mac OS Server 5.2
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-200
7.5
2017-03-31 CVE-2017-1154 Information Exposure vulnerability in IBM Algo ONE 4.9.1/5.0.0/5.1.0
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users.
network
low complexity
ibm CWE-200
6.5
2017-03-30 CVE-2017-5184 Information Exposure vulnerability in Microfocus Sentinel 8.0/8.0.0.1
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).
network
low complexity
microfocus CWE-200
5.3
2017-03-30 CVE-2016-7542 Information Exposure vulnerability in Fortinet Fortios
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
network
low complexity
fortinet CWE-200
4.9
2017-03-29 CVE-2017-4977 Information Exposure vulnerability in EMC RSA Archer Security Operations Management 1.3.1.51
EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.
local
high complexity
emc CWE-200
7.0
2017-03-29 CVE-2016-6349 Information Exposure vulnerability in Projectatomic Oci-Register-Machine
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
local
low complexity
projectatomic CWE-200
3.3