Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-09-18 CVE-2016-4746 Information Exposure vulnerability in Apple Iphone OS
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.
network
low complexity
apple CWE-200
5.3
2016-09-18 CVE-2016-4740 Information Exposure vulnerability in Apple Iphone OS
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
local
high complexity
apple CWE-200
2.9
2016-09-18 CVE-2016-4719 Information Exposure vulnerability in Apple Iphone OS and Watchos
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.
local
low complexity
apple CWE-200
5.5
2016-09-18 CVE-2016-4620 Information Exposure vulnerability in Apple Iphone OS
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.
local
low complexity
apple CWE-200
3.3
2016-09-18 CVE-2016-0929 Information Exposure vulnerability in Pivotal Software Rabbitmq
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
network
low complexity
pivotal-software CWE-200
7.5
2016-09-17 CVE-2016-6644 Information Exposure vulnerability in EMC Documentum D2 4.5/4.6
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
network
low complexity
emc CWE-200
5.3
2016-09-16 CVE-2016-7420 Information Exposure vulnerability in Cryptopp Crypto++
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
network
high complexity
cryptopp CWE-200
5.9
2016-09-16 CVE-2016-6936 Information Exposure vulnerability in Adobe AIR SDK & Compiler 22.0.0.153
Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attackers to obtain sensitive information by leveraging access to a network over which analytics data is sent.
network
low complexity
adobe CWE-200
7.5
2016-09-14 CVE-2016-3374 Information Exposure vulnerability in Microsoft products
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
network
low complexity
microsoft CWE-200
6.5
2016-09-14 CVE-2016-3371 Information Exposure vulnerability in Microsoft products
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-200
5.5