Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-12-08 CVE-2016-9839 Information Exposure vulnerability in Osgeo Mapserver
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
network
low complexity
osgeo CWE-200
7.5
2016-12-01 CVE-2016-3012 Information Exposure vulnerability in IBM API Connect and Network Path Manager
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
network
low complexity
ibm CWE-200
7.5
2016-11-30 CVE-2016-3002 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
low complexity
ibm CWE-200
2.1
2016-11-30 CVE-2016-2958 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.
network
low complexity
ibm CWE-200
4.3
2016-11-30 CVE-2016-2957 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
network
low complexity
ibm CWE-200
4.3
2016-11-30 CVE-2016-2952 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
network
high complexity
ibm CWE-200
3.7
2016-11-30 CVE-2016-2949 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
local
low complexity
ibm CWE-200
3.3
2016-11-30 CVE-2016-2940 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.
network
low complexity
ibm CWE-200
5.3
2016-11-30 CVE-2016-2931 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
network
low complexity
ibm CWE-200
5.3
2016-11-29 CVE-2016-5765 Information Exposure vulnerability in Microfocus products
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.
network
low complexity
microfocus CWE-200
6.5