Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-04-10 CVE-2019-0040 Information Exposure vulnerability in Juniper Junos
On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI).
network
low complexity
juniper CWE-200
critical
9.1
2019-04-09 CVE-2018-13366 Information Exposure vulnerability in Fortinet Fortios
An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.
network
low complexity
fortinet CWE-200
5.3
2019-04-09 CVE-2019-10243 Information Exposure vulnerability in Eclipse Kura
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies.
network
low complexity
eclipse CWE-200
5.3
2019-04-08 CVE-2019-4051 Information Exposure vulnerability in IBM API Connect
Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses.
network
low complexity
ibm CWE-200
5.3
2019-04-08 CVE-2018-1999 Information Exposure vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system.
network
low complexity
ibm CWE-200
4.3
2019-04-08 CVE-2018-1885 Information Exposure vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request.
network
low complexity
ibm CWE-200
5.3
2019-04-04 CVE-2018-20449 Information Exposure vulnerability in multiple products
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.
local
low complexity
linux netapp CWE-200
5.5
2019-04-04 CVE-2018-11971 Information Exposure vulnerability in Qualcomm products
Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 615/16/SD 415, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130
local
low complexity
qualcomm CWE-200
5.5
2019-04-03 CVE-2018-4445 Information Exposure vulnerability in Apple Iphone OS
"Clear History and Website Data" did not clear the history.
network
low complexity
apple CWE-200
4.3
2019-04-03 CVE-2018-4431 Information Exposure vulnerability in Apple products
A memory initialization issue was addressed with improved memory handling.
local
low complexity
apple CWE-200
5.5