Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-03-18 CVE-2016-1994 Information Exposure vulnerability in HP System Management Homepage
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.
network
low complexity
hp CWE-200
6.5
2016-03-17 CVE-2016-1992 Information Exposure vulnerability in HP products
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.
network
low complexity
hp CWE-200
6.5
2016-03-13 CVE-2016-1967 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session.
network
low complexity
mozilla CWE-200
6.5
2016-03-13 CVE-2016-1955 Information Exposure vulnerability in multiple products
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
network
low complexity
novell opensuse mozilla CWE-200
4.3
2016-03-12 CVE-2016-0831 Information Exposure vulnerability in Google Android
The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25778215.
local
low complexity
google CWE-200
5.5
2016-03-12 CVE-2016-0823 Information Exposure vulnerability in multiple products
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
local
low complexity
google linux CWE-200
4.0
2016-03-12 CVE-2016-1562 Information Exposure vulnerability in DTE Energy Insight 1.7.7
The REST API in the DTE Energy Insight application before 1.7.8 for Android allows remote authenticated users to obtain unspecified customer information via a SQL expression in the filter parameter.
network
low complexity
dte-energy CWE-200
4.3
2016-03-12 CVE-2016-1360 Information Exposure vulnerability in Cisco Prime LAN Management Solution
Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390.
local
low complexity
cisco CWE-200
7.1
2016-03-12 CVE-2015-6485 Information Exposure vulnerability in Schneider-Electric Telvent RTU Firmware C3413500001D3/C3414500S02J1
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.
network
low complexity
schneider-electric CWE-200
5.3
2016-03-09 CVE-2016-0886 Information Exposure vulnerability in EMC Documentum XCP 2.1/2.2
EMC Documentum xCP 2.1 before patch 24 and 2.2 before patch 12 allows remote authenticated users to obtain sensitive user-account metadata via a members/xcp_member API call.
network
low complexity
emc CWE-200
4.3