Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-07-15 CVE-2019-1071 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-07-15 CVE-2014-10374 Information Exposure vulnerability in Fitbit Charge 2 Firmware
On Fitbit activity-tracker devices, certain addresses never change.
low complexity
fitbit CWE-200
6.5
2019-07-15 CVE-2019-1010024 Information Exposure vulnerability in GNU Glibc
GNU Libc current is affected by: Mitigation bypass.
network
low complexity
gnu CWE-200
5.3
2019-07-11 CVE-2019-4193 Information Exposure vulnerability in IBM Jazz for Service Management
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters.
network
low complexity
ibm CWE-200
7.5
2019-07-11 CVE-2018-1968 Information Exposure vulnerability in IBM Security Identity Manager Virtual Appliance 7.0.1/7.0.1.12
IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2019-07-10 CVE-2018-14831 Information Exposure vulnerability in Damicms 6.0.0
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
network
low complexity
damicms CWE-200
4.9
2019-07-09 CVE-2019-11991 Information Exposure vulnerability in HP 3Par Service Processor Firmware 4.1/4.4
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4.
network
low complexity
hp CWE-200
critical
9.8
2019-07-05 CVE-2018-14529 Information Exposure vulnerability in Invoxia Nvx220 Firmware
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.
network
low complexity
invoxia CWE-200
7.5
2019-07-05 CVE-2019-13314 Information Exposure vulnerability in Redhat Virt-Bootstrap 1.1.0
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
local
low complexity
redhat CWE-200
7.8
2019-07-05 CVE-2019-13313 Information Exposure vulnerability in multiple products
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
local
low complexity
libosinfo fedoraproject redhat CWE-200
7.8