Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-06-11 CVE-2020-13702 Information Exposure vulnerability in the Rolling Proximity Identifier Project the Rolling Proximity Identifier 20200529
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID.
network
low complexity
the-rolling-proximity-identifier-project CWE-200
critical
10.0
2020-06-08 CVE-2020-1775 Information Exposure vulnerability in Otrs
BCC recipients in mails sent from OTRS are visible in article detail on external interface.
network
low complexity
otrs CWE-200
4.3
2020-06-04 CVE-2019-20836 Information Exposure vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.5.
network
low complexity
foxitsoftware CWE-200
7.5
2020-06-04 CVE-2018-21242 Information Exposure vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit PhantomPDF before 8.3.6.
network
low complexity
foxitsoftware CWE-200
critical
9.8
2020-06-04 CVE-2020-7030 Information Exposure vulnerability in Avaya IP Office
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component.
local
low complexity
avaya CWE-200
5.5
2020-06-03 CVE-2011-2863 Information Exposure vulnerability in Google Chrome
Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google CWE-200
6.5
2020-06-03 CVE-2020-13597 Information Exposure vulnerability in Projectcalico Calico
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused.
network
high complexity
projectcalico CWE-200
3.5
2020-06-02 CVE-2020-13764 Information Exposure vulnerability in Rocketgenius Gravityforms
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
network
low complexity
rocketgenius CWE-200
7.5
2020-06-01 CVE-2014-8940 Information Exposure vulnerability in Piwigo Lexiglot
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.
network
low complexity
piwigo CWE-200
5.3
2020-05-29 CVE-2020-5573 Information Exposure vulnerability in Cybozu Kintone
Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in the product via unspecified vectors.
low complexity
cybozu CWE-200
4.6