Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-09-18 CVE-2016-0929 Information Exposure vulnerability in Pivotal Software Rabbitmq
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
network
low complexity
pivotal-software CWE-200
7.5
2016-09-17 CVE-2016-6644 Information Exposure vulnerability in EMC Documentum D2 4.5/4.6
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
network
low complexity
emc CWE-200
5.3
2016-09-16 CVE-2016-7420 Information Exposure vulnerability in Cryptopp Crypto++
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
network
high complexity
cryptopp CWE-200
5.9
2016-09-16 CVE-2016-6936 Information Exposure vulnerability in Adobe AIR SDK & Compiler 22.0.0.153
Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attackers to obtain sensitive information by leveraging access to a network over which analytics data is sent.
network
low complexity
adobe CWE-200
7.5
2016-09-14 CVE-2016-3374 Information Exposure vulnerability in Microsoft products
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
network
low complexity
microsoft CWE-200
6.5
2016-09-14 CVE-2016-3371 Information Exposure vulnerability in Microsoft products
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2016-09-14 CVE-2016-3370 Information Exposure vulnerability in Microsoft products
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3374.
network
low complexity
microsoft CWE-200
6.5
2016-09-14 CVE-2016-3344 Information Exposure vulnerability in Microsoft Windows 10 1511
The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
3.3
2016-09-14 CVE-2016-3325 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
3.1
2016-09-14 CVE-2016-3291 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
2.4