Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-06-09 CVE-2016-1582 Information Exposure vulnerability in Canonical LXD and Ubuntu Linux
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
local
low complexity
canonical CWE-200
5.5
2016-06-08 CVE-2016-3711 Information Exposure vulnerability in Redhat Openshift and Openshift Origin
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
local
low complexity
redhat CWE-200
3.3
2016-06-08 CVE-2016-2149 Information Exposure vulnerability in Redhat Openshift 3.2
Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.
network
low complexity
redhat CWE-200
6.5
2016-06-08 CVE-2016-2142 Information Exposure vulnerability in Redhat Openshift 3.1
Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.
local
low complexity
redhat CWE-200
5.5
2016-06-08 CVE-2016-4367 Information Exposure vulnerability in HP Universal Cmbd Foundation
The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
hp CWE-200
7.5
2016-06-08 CVE-2016-2027 Information Exposure vulnerability in HP products
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026.
network
low complexity
hp CWE-200
7.5
2016-06-08 CVE-2016-2026 Information Exposure vulnerability in HP products
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027.
network
low complexity
hp CWE-200
7.5
2016-06-07 CVE-2015-5231 Information Exposure vulnerability in multiple products
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
local
low complexity
criu opensuse CWE-200
5.5
2016-06-06 CVE-2015-5041 Information Exposure vulnerability in multiple products
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
network
low complexity
ibm suse redhat CWE-200
critical
9.1
2016-06-05 CVE-2016-1698 Information Exposure vulnerability in multiple products
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
network
low complexity
debian redhat suse opensuse google CWE-200
6.5