Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-09-26 CVE-2016-6827 Information Exposure vulnerability in Huawei Fusioncompute
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
network
low complexity
huawei CWE-200
6.5
2016-09-26 CVE-2016-3639 Information Exposure vulnerability in SAP Hana DB 1.00.091.00.1418659308
SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified HTTP request, aka SAP Security Note 2176128.
network
low complexity
sap CWE-200
4.3
2016-09-26 CVE-2016-5976 Information Exposure vulnerability in IBM Tealeaf Customer Experience
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to discover component passwords via unspecified vectors.
network
low complexity
ibm CWE-200
4.9
2016-09-26 CVE-2016-5970 Information Exposure vulnerability in IBM Security Privileged Identity Manager Virtual Appliance 2.0/2.0.2
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a ..
network
low complexity
ibm CWE-200
6.5
2016-09-26 CVE-2016-5946 Information Exposure vulnerability in IBM products
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a ..
network
low complexity
ibm CWE-200
6.5
2016-09-26 CVE-2016-2999 Information Exposure vulnerability in IBM Connections
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
network
low complexity
ibm CWE-200
6.5
2016-09-26 CVE-2016-0248 Information Exposure vulnerability in IBM Security Guardium 10.0/9.0
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
network
high complexity
ibm CWE-200
3.7
2016-09-25 CVE-2016-5172 Information Exposure vulnerability in multiple products
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
network
low complexity
google nodejs debian CWE-200
6.5
2016-09-25 CVE-2016-4771 Information Exposure vulnerability in Apple Iphone OS
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname.
local
low complexity
apple CWE-200
5.5
2016-09-25 CVE-2016-4758 Information Exposure vulnerability in Apple Safari
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.
network
low complexity
apple CWE-200
6.5