Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-08-19 CVE-2016-4995 Information Exposure vulnerability in Theforeman Foreman
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
network
high complexity
theforeman CWE-200
5.3
2016-08-10 CVE-2013-7458 Information Exposure vulnerability in multiple products
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
local
low complexity
redislabs debian CWE-200
3.3
2016-08-09 CVE-2016-3329 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence of files via a crafted webpage, aka "Internet Explorer Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
5.3
2016-08-09 CVE-2016-3327 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3326.
network
high complexity
microsoft CWE-200
5.3
2016-08-09 CVE-2016-3326 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3327.
network
high complexity
microsoft CWE-200
5.3
2016-08-09 CVE-2016-3321 Information Exposure vulnerability in Microsoft Internet Explorer 10/11
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability."
local
high complexity
microsoft CWE-200
2.5
2016-08-09 CVE-2016-3315 Information Exposure vulnerability in Microsoft Onenote and Onenote for mac
Microsoft OneNote 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to obtain sensitive information via a crafted OneNote file, aka "Microsoft OneNote Information Disclosure Vulnerability."
local
low complexity
microsoft CWE-200
5.5
2016-08-09 CVE-2016-3312 Information Exposure vulnerability in Microsoft Windows 10 1511
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-200
critical
9.1
2016-08-09 CVE-2016-4253 Information Exposure vulnerability in Adobe Experience Manager
The Backup functionality in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows attackers to obtain sensitive information via unspecified vectors.
network
low complexity
adobe CWE-200
5.3
2016-08-09 CVE-2016-4169 Information Exposure vulnerability in Adobe Experience Manager 6.0.0/6.1.0/6.2.0
Adobe Experience Manager 6.0, 6.1, and 6.2 allow attackers to obtain sensitive audit log event information via unspecified vectors.
network
low complexity
adobe CWE-200
5.3