Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-08-05 CVE-2016-3834 Information Exposure vulnerability in Google Android
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.
local
low complexity
google CWE-200
5.5
2016-08-05 CVE-2016-5392 Information Exposure vulnerability in Redhat Openshift 3.2
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list.
network
low complexity
redhat CWE-200
6.5
2016-08-05 CVE-2016-6149 Information Exposure vulnerability in SAP Hana Sps09 1.00.091.00.14186593
SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.
local
low complexity
sap CWE-200
5.5
2016-08-05 CVE-2016-6145 Information Exposure vulnerability in SAP Hana DB 1.00.091.00.1418659308
The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.
network
low complexity
sap CWE-200
5.3
2016-08-05 CVE-2016-3640 Information Exposure vulnerability in SAP Hana DB 1.00.091.00.14186593
The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password information via vectors related to passwords in Web Dispatcher trace files, aka SAP Security Note 2148905.
local
low complexity
sap CWE-200
5.5
2016-08-05 CVE-2016-5265 Information Exposure vulnerability in multiple products
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.
local
high complexity
oracle mozilla CWE-200
5.5
2016-08-05 CVE-2016-5260 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.
network
low complexity
mozilla CWE-200
6.5
2016-08-05 CVE-2016-5250 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.
network
low complexity
mozilla CWE-200
4.3
2016-08-05 CVE-2016-2830 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.
network
low complexity
mozilla CWE-200
4.3
2016-07-26 CVE-2015-5738 Information Exposure vulnerability in multiple products
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
network
low complexity
marvell f5 CWE-200
7.5