Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-11-25 CVE-2016-6748 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-6746 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-6721 Information Exposure vulnerability in Google Android 6.0/6.0.1/7.0
An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-6718 Information Exposure vulnerability in Google Android
An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to retrieve sensitive information without user interaction.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-6710 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-6709 Information Exposure vulnerability in Google Android 6.0/6.0.1/7.0
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application.
network
high complexity
google CWE-200
5.9
2016-11-25 CVE-2016-6698 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-3907 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-3906 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-2947 Information Exposure vulnerability in IBM products
IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to obtain sensitive information via unspecified vectors.
network
low complexity
ibm CWE-200
2.7