Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-02-21 CVE-2017-6071 Information Exposure vulnerability in Cmsmadesimple CMS Made Simple and Form Builder
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
network
low complexity
cmsmadesimple CWE-200
5.3
2017-02-21 CVE-2017-6070 Information Exposure vulnerability in Cmsmadesimple CMS Made Simple and Form Builder
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.
network
low complexity
cmsmadesimple CWE-200
critical
9.8
2017-02-21 CVE-2016-9314 Information Exposure vulnerability in Trendmicro Interscan web Security Virtual Appliance
Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to backup the system configuration and download it onto their local machine.
local
low complexity
trendmicro CWE-200
7.8
2017-02-20 CVE-2017-0038 Information Exposure vulnerability in Microsoft products
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions.
local
low complexity
microsoft CWE-200
5.5
2017-02-20 CVE-2016-6249 Information Exposure vulnerability in F5 products
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log.
local
low complexity
f5 CWE-200
5.3
2017-02-20 CVE-2017-2365 Information Exposure vulnerability in multiple products
An issue was discovered in certain Apple products.
network
low complexity
apple webkitgtk CWE-200
6.5
2017-02-20 CVE-2017-2364 Information Exposure vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-200
6.5
2017-02-20 CVE-2017-2363 Information Exposure vulnerability in multiple products
An issue was discovered in certain Apple products.
network
low complexity
apple webkitgtk CWE-200
6.5
2017-02-20 CVE-2017-2357 Information Exposure vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-200
3.3
2017-02-20 CVE-2017-2350 Information Exposure vulnerability in multiple products
An issue was discovered in certain Apple products.
network
low complexity
apple webkitgtk CWE-200
6.5