Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-02-12 CVE-2011-3901 Information Exposure vulnerability in Google Android 2.3.7
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
network
low complexity
google CWE-200
7.5
2020-02-12 CVE-2011-2343 Information Exposure vulnerability in Google Android
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
low complexity
google CWE-200
2.4
2020-02-12 CVE-2013-6681 Information Exposure vulnerability in Mapway Tube MAP 3.0.21
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability
network
high complexity
mapway CWE-200
5.9
2020-02-10 CVE-2017-18642 Information Exposure vulnerability in Syska Smartlight Rainbow LED Smart Bulb Firmware 20170806
Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineering, and replay attacks.
low complexity
syska CWE-200
6.5
2020-02-10 CVE-2012-5828 Information Exposure vulnerability in Blackberry Playbook Firmware
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
network
low complexity
blackberry CWE-200
6.5
2020-02-10 CVE-2012-1994 Information Exposure vulnerability in HP Systems Insight Manager
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
low complexity
hp CWE-200
5.7
2020-02-08 CVE-2012-5570 Information Exposure vulnerability in Basic Webmail Project Basic Webmail 6.X1.0/6.X1.1/6.X1.X
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
network
low complexity
basic-webmail-project CWE-200
4.3
2020-02-08 CVE-2014-9127 Information Exposure vulnerability in Open-School 2.2
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.
network
low complexity
open-school CWE-200
6.5
2020-02-08 CVE-2014-7863 Information Exposure vulnerability in Zohocorp products
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
network
low complexity
zohocorp CWE-200
7.5
2020-02-07 CVE-2013-0192 Information Exposure vulnerability in Simplemachines Simple Machines Forum
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
network
low complexity
simplemachines CWE-200
4.9