Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-09-25 CVE-2016-4755 Information Exposure vulnerability in Apple mac OS X
Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
apple CWE-200
5.5
2016-09-25 CVE-2016-4752 Information Exposure vulnerability in Apple mac OS X
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
local
low complexity
apple CWE-200
5.5
2016-09-25 CVE-2016-4745 Information Exposure vulnerability in Apple mac OS X
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.
network
low complexity
apple CWE-200
5.3
2016-09-25 CVE-2016-4742 Information Exposure vulnerability in Apple mac OS X
NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app.
local
low complexity
apple CWE-200
5.5
2016-09-25 CVE-2016-4739 Information Exposure vulnerability in Apple mac OS X
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.
network
high complexity
apple CWE-200
3.7
2016-09-25 CVE-2016-4715 Information Exposure vulnerability in Apple mac OS X
The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.
local
low complexity
apple CWE-200
3.3
2016-09-25 CVE-2016-4713 Information Exposure vulnerability in Apple mac OS X
CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.
network
high complexity
apple CWE-200
5.3
2016-09-25 CVE-2016-4708 Information Exposure vulnerability in Apple products
CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.
network
low complexity
apple CWE-200
6.5
2016-09-24 CVE-2016-0918 Information Exposure vulnerability in EMC products
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.
network
low complexity
emc CWE-200
4.3
2016-09-22 CVE-2016-5282 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.
network
low complexity
mozilla CWE-200
6.5