Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-11-03 CVE-2016-9086 Information Exposure vulnerability in Gitlab
GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab.
network
low complexity
gitlab CWE-200
6.5
2016-10-28 CVE-2016-8889 Information Exposure vulnerability in Bitcoin Knots Project Bitcoin Knots
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
local
low complexity
bitcoin-knots-project CWE-200
6.2
2016-10-28 CVE-2016-8871 Information Exposure vulnerability in Botan Project Botan
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
local
low complexity
botan-project CWE-200
6.2
2016-10-27 CVE-2016-6446 Information Exposure vulnerability in Cisco Meeting Server
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server.
network
low complexity
cisco CWE-200
7.5
2016-10-25 CVE-2016-8295 Information Exposure vulnerability in Oracle Peoplesoft Enterprise Human Capital Management Time and Labor 9.2
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors.
network
low complexity
oracle CWE-200
4.3
2016-10-25 CVE-2016-8294 Information Exposure vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.54/8.55
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors.
network
low complexity
oracle CWE-200
4.3
2016-10-25 CVE-2016-8286 Information Exposure vulnerability in Oracle Mysql
Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote authenticated users to affect confidentiality via vectors related to Server: Security: Privileges.
network
high complexity
oracle CWE-200
3.1
2016-10-25 CVE-2016-5618 Information Exposure vulnerability in Oracle Data Integrator
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.2.0.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Code Generation Engine.
network
high complexity
oracle CWE-200
3.1
2016-10-25 CVE-2016-5611 Information Exposure vulnerability in Oracle VM Virtualbox
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality via vectors related to Core.
local
low complexity
oracle CWE-200
4.3
2016-10-25 CVE-2016-5603 Information Exposure vulnerability in Oracle Flexcube Universal Banking
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to INFRA, a different vulnerability than CVE-2016-5621.
network
low complexity
oracle CWE-200
4.3