Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-01-27 CVE-2015-8618 Information Exposure vulnerability in multiple products
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
network
low complexity
opensuse golang CWE-200
7.5
2016-01-27 CVE-2015-7488 Information Exposure vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors.
local
high complexity
ibm CWE-200
5.9
2016-01-27 CVE-2015-7487 Information Exposure vulnerability in IBM products
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow local users to obtain sensitive information by leveraging administrative privileges and reading log files.
local
high complexity
ibm CWE-200
4.1
2016-01-26 CVE-2016-1490 Information Exposure vulnerability in Lenovo Shareit 2.5.1.1
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.
low complexity
lenovo CWE-200
4.1
2016-01-25 CVE-2016-1618 Information Exposure vulnerability in Google Chrome
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
network
low complexity
google CWE-200
6.5
2016-01-25 CVE-2016-1617 Information Exposure vulnerability in Google Chrome
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.
network
low complexity
google CWE-200
4.3
2016-01-25 CVE-2016-1614 Information Exposure vulnerability in Google Chrome
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
network
low complexity
google CWE-200
4.3
2016-01-19 CVE-2016-1903 Information Exposure vulnerability in PHP
The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.
network
low complexity
php CWE-200
critical
9.1
2016-01-18 CVE-2016-0201 Information Exposure vulnerability in IBM Security Network Protection Firmware 5.3.1/5.3.2
GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision.
network
high complexity
ibm CWE-200
5.9
2016-01-18 CVE-2015-7886 Information Exposure vulnerability in Netapp Data Ontap
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.
network
high complexity
netapp CWE-200
3.7