Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-07-25 CVE-2018-13897 Information Exposure vulnerability in Qualcomm products
Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660
network
low complexity
qualcomm CWE-200
7.5
2019-07-18 CVE-2019-8286 Information Exposure vulnerability in Kaspersky products
Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link).
network
low complexity
kaspersky CWE-200
4.3
2019-07-17 CVE-2019-1010283 Information Exposure vulnerability in Univention Corporate Server
Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.
network
low complexity
univention CWE-200
7.5
2019-07-17 CVE-2018-2022 Information Exposure vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2019-07-16 CVE-2019-1575 Information Exposure vulnerability in Paloaltonetworks Pan-Os
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
network
low complexity
paloaltonetworks CWE-200
8.8
2019-07-15 CVE-2019-1116 Information Exposure vulnerability in Microsoft Windows 7 and Windows Server 2008
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-200
6.5
2019-07-15 CVE-2019-1112 Information Exposure vulnerability in Microsoft Office and Office 365 Proplus
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-07-15 CVE-2019-1108 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-200
6.5
2019-07-15 CVE-2019-1101 Information Exposure vulnerability in Microsoft Windows 7 and Windows Server 2008
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-200
6.5
2019-07-15 CVE-2019-1100 Information Exposure vulnerability in Microsoft Windows 7 and Windows Server 2008
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-200
6.5