Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-07-23 CVE-2016-5137 Information Exposure vulnerability in Google Chrome
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.
network
low complexity
google CWE-200
4.3
2016-07-23 CVE-2016-5134 Information Exposure vulnerability in Google Chrome
net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, a related issue to CVE-2016-3763.
network
low complexity
google CWE-200
8.8
2016-07-22 CVE-2016-5744 Information Exposure vulnerability in Siemens Simatic Wincc 7.0/7.2
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
network
low complexity
siemens CWE-200
7.5
2016-07-22 CVE-2016-4648 Information Exposure vulnerability in Apple mac OS X
Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.
local
low complexity
apple CWE-200
5.5
2016-07-22 CVE-2016-4646 Information Exposure vulnerability in Apple mac OS X
Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted audio file.
network
low complexity
apple CWE-200
6.5
2016-07-22 CVE-2016-4645 Information Exposure vulnerability in Apple mac OS X
CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
apple CWE-200
3.3
2016-07-22 CVE-2016-4635 Information Exposure vulnerability in Apple Iphone OS
FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.
network
high complexity
apple CWE-200
5.3
2016-07-22 CVE-2016-4595 Information Exposure vulnerability in Apple mac OS X
Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure.
low complexity
apple CWE-200
4.6
2016-07-22 CVE-2016-4593 Information Exposure vulnerability in Apple Iphone OS
The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.
low complexity
apple CWE-200
2.4
2016-07-17 CVE-2016-0393 Information Exposure vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
network
low complexity
ibm CWE-200
5.3