Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2016-01-17 CVE-2015-7470 Information Exposure vulnerability in IBM Jazz Reporting Service
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.
network
low complexity
ibm CWE-200
7.5
2016-01-17 CVE-2015-4958 Information Exposure vulnerability in IBM Infosphere Master Data Management
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.
local
low complexity
ibm CWE-200
3.3
2016-01-16 CVE-2016-1295 Information Exposure vulnerability in Cisco Adaptive Security Appliance Software
Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.
network
low complexity
cisco CWE-200
5.3
2016-01-15 CVE-2016-1910 Information Exposure vulnerability in SAP Netweaver 7.40
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
network
low complexity
sap CWE-200
5.3
2016-01-15 CVE-2015-8749 Information Exposure vulnerability in Openstack Nova
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.
network
high complexity
openstack CWE-200
5.9
2016-01-15 CVE-2016-1898 Information Exposure vulnerability in multiple products
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
local
low complexity
ffmpeg canonical opensuse CWE-200
5.5
2016-01-15 CVE-2016-1897 Information Exposure vulnerability in multiple products
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
local
low complexity
ffmpeg canonical opensuse CWE-200
5.5
2016-01-15 CVE-2016-0853 Information Exposure vulnerability in Advantech Webaccess
Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.
network
low complexity
advantech CWE-200
7.5
2016-01-15 CVE-2015-8280 Information Exposure vulnerability in Samsung web Viewer 1.0.0.193
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.
network
low complexity
samsung CWE-200
7.5
2016-01-15 CVE-2015-3943 Information Exposure vulnerability in Advantech Webaccess
Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.
network
low complexity
advantech CWE-200
5.3