Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2017-02-07 CVE-2016-6097 Information Exposure vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
4.0
2017-02-07 CVE-2016-6094 Information Exposure vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
network
low complexity
ibm CWE-200
4.3
2017-02-07 CVE-2016-6092 Information Exposure vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-200
6.2
2017-02-07 CVE-2015-5677 Information Exposure vulnerability in Freebsd 10.1/10.2/9.3
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.
local
low complexity
freebsd CWE-200
5.5
2017-02-06 CVE-2017-5595 Information Exposure vulnerability in Zoneminder
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data).
local
low complexity
zoneminder CWE-200
5.5
2017-02-06 CVE-2016-9772 Information Exposure vulnerability in Openafs
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
network
low complexity
openafs CWE-200
5.3
2017-02-06 CVE-2017-5550 Information Exposure vulnerability in Linux Kernel
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.
local
low complexity
linux CWE-200
5.5
2017-02-03 CVE-2016-8217 Information Exposure vulnerability in Dell Bsafe Crypto-J
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability.
network
high complexity
dell CWE-200
3.7
2017-02-03 CVE-2016-0890 Information Exposure vulnerability in EMC Powerpath Virtual Appliance 2.0
EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users to compromise the affected system.
network
high complexity
emc CWE-200
6.4
2017-02-02 CVE-2016-6116 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.9