Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-12-15 CVE-2016-6852 Information Exposure vulnerability in Open-Xchange Appsuite 7.8.2
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8.
network
low complexity
open-xchange CWE-200
4.3
2016-12-15 CVE-2016-4027 Information Exposure vulnerability in Open-Xchange Appsuite 7.8.1
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10.
network
low complexity
open-xchange CWE-200
3.5
2016-12-14 CVE-2016-6471 Information Exposure vulnerability in Cisco Firesight System Software 5.4.1.6
A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remote attacker to view the Remote Storage Password.
network
low complexity
cisco CWE-200
6.5
2016-12-14 CVE-2016-6464 Information Exposure vulnerability in Cisco Unified Communications Manager IM and Presence Service
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted.
network
low complexity
cisco CWE-200
7.5
2016-12-13 CVE-2016-6313 Information Exposure vulnerability in multiple products
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
network
low complexity
gnupg debian canonical CWE-200
5.3
2016-12-13 CVE-2016-6722 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-12-13 CVE-2016-6720 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-12-13 CVE-2015-5073 Information Exposure vulnerability in multiple products
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.
network
low complexity
ibm pcre CWE-200
critical
9.1
2016-12-11 CVE-2016-9855 Information Exposure vulnerability in PHPmyadmin
An issue was discovered in phpMyAdmin.
network
low complexity
phpmyadmin CWE-200
5.3
2016-12-11 CVE-2016-9854 Information Exposure vulnerability in PHPmyadmin
An issue was discovered in phpMyAdmin.
network
low complexity
phpmyadmin CWE-200
5.3