Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-05-17 CVE-2016-3674 Information Exposure vulnerability in multiple products
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
network
low complexity
fedoraproject debian xstream-project CWE-200
7.5
2016-05-17 CVE-2016-0306 Information Exposure vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
network
high complexity
ibm CWE-200
5.9
2016-05-15 CVE-2016-0341 Information Exposure vulnerability in IBM products
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
ibm CWE-200
7.5
2016-05-14 CVE-2016-2298 Information Exposure vulnerability in Meteocontrol products
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.
network
low complexity
meteocontrol CWE-200
critical
9.8
2016-05-14 CVE-2016-1206 Information Exposure vulnerability in Iodata Wn-Gdn/R3 Firmware
The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack.
low complexity
iodata CWE-200
4.3
2016-05-14 CVE-2016-2015 Information Exposure vulnerability in HP System Management Homepage
HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.
local
low complexity
hp CWE-200
7.1
2016-05-14 CVE-2016-1208 Information Exposure vulnerability in multiple products
The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.
network
low complexity
apple filemaker CWE-200
7.5
2016-05-13 CVE-2016-4536 Information Exposure vulnerability in Openafs
The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to obtain sensitive memory information by leveraging access to RPC call traffic.
network
low complexity
openafs CWE-200
5.3
2016-05-13 CVE-2016-2849 Information Exposure vulnerability in multiple products
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
network
low complexity
debian fedoraproject botan-project CWE-200
7.5
2016-05-13 CVE-2015-7827 Information Exposure vulnerability in multiple products
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
network
low complexity
fedoraproject botan-project debian CWE-200
7.5