Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-12-20 CVE-2016-7278 Information Exposure vulnerability in Microsoft Internet Explorer 10/11/9
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Hyperlink Object Library Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
5.3
2016-12-20 CVE-2016-7258 Information Exposure vulnerability in Microsoft Windows 10 and Windows Server 2016
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2016-12-20 CVE-2016-7257 Information Exposure vulnerability in Microsoft products
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
6.5
2016-12-20 CVE-2016-7219 Information Exposure vulnerability in Microsoft products
The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Crypto Driver Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2016-12-19 CVE-2016-10005 Information Exposure vulnerability in SAP Solution Manager 7.1/7.20/7.31
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.
network
low complexity
sap CWE-200
7.5
2016-12-17 CVE-2016-9159 Information Exposure vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl.
network
high complexity
siemens CWE-200
5.9
2016-12-15 CVE-2015-3271 Information Exposure vulnerability in Apache Tika 1.9
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
network
low complexity
apache CWE-200
5.3
2016-12-15 CVE-2016-7889 Information Exposure vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.2 and earlier has an issue with parsing crafted XML entries that could lead to information disclosure.
network
low complexity
adobe CWE-200
7.5
2016-12-15 CVE-2016-7888 Information Exposure vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak.
network
low complexity
adobe CWE-200
5.3
2016-12-15 CVE-2016-7887 Information Exposure vulnerability in Adobe Coldfusion Builder
Adobe ColdFusion Builder versions 2016 update 2 and earlier, 3.0.3 and earlier have an important vulnerability that could lead to information disclosure.
network
low complexity
adobe CWE-200
7.5