Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-05-05 CVE-2016-2107 Information Exposure vulnerability in multiple products
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session.
5.9
2016-05-03 CVE-2016-0893 Information Exposure vulnerability in EMC RSA Data Loss Prevention
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to obtain sensitive information by reading error messages.
network
low complexity
emc CWE-200
4.3
2016-05-02 CVE-2016-2117 Information Exposure vulnerability in multiple products
The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.
network
low complexity
oracle canonical linux CWE-200
7.5
2016-05-02 CVE-2015-4176 Information Exposure vulnerability in Linux Kernel
fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.
local
low complexity
linux CWE-200
5.5
2016-04-30 CVE-2016-2813 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
network
low complexity
mozilla CWE-200
6.5
2016-04-30 CVE-2016-1199 Information Exposure vulnerability in Lockon Ec-Cube
The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a different vulnerability than CVE-2016-1200.
network
low complexity
lockon CWE-200
5.3
2016-04-25 CVE-2016-1185 Information Exposure vulnerability in Cybozu Kintone
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.
local
high complexity
cybozu CWE-200
2.5
2016-04-22 CVE-2016-1595 Information Exposure vulnerability in Novell Service Desk 7.1
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
network
low complexity
novell CWE-200
6.5
2016-04-22 CVE-2016-1594 Information Exposure vulnerability in Novell Service Desk 7.1
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
network
low complexity
novell CWE-200
6.5
2016-04-22 CVE-2016-3145 Information Exposure vulnerability in Lexmark Printer Firmware
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.
low complexity
lexmark CWE-200
4.6