Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2018-08-29 CVE-2018-6599 Information Exposure Through Log Files vulnerability in Orbic Wonder Rc555L Firmware 7.1/7.1.2
An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card.
local
low complexity
orbic CWE-532
5.5
2018-08-12 CVE-2018-3776 Information Exposure Through Log Files vulnerability in Nextcloud Server
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
network
low complexity
nextcloud CWE-532
5.3
2018-08-10 CVE-2018-7754 Information Exposure Through Log Files vulnerability in Linux Kernel
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.
local
low complexity
linux CWE-532
5.5
2018-08-01 CVE-2018-1999036 Information Exposure Through Log Files vulnerability in Jenkins SSH Agent
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.
network
low complexity
jenkins CWE-532
6.5
2018-07-27 CVE-2017-15113 Information Exposure Through Log Files vulnerability in multiple products
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking.
network
high complexity
ovirt redhat CWE-532
6.6
2018-07-25 CVE-2018-6971 Information Exposure Through Log Files vulnerability in VMWare Horizon View Agents
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations).
local
low complexity
vmware CWE-532
7.8
2018-07-16 CVE-2018-11717 Information Exposure Through Log Files vulnerability in Zohocorp Manageengine Desktop Central
An issue was discovered in Zoho ManageEngine Desktop Central before 100251.
network
low complexity
zohocorp CWE-532
critical
9.8
2018-07-16 CVE-2018-11716 Information Exposure Through Log Files vulnerability in Zohocorp Manageengine Desktop Central
An issue was discovered in Zoho ManageEngine Desktop Central before 100230.
network
low complexity
zohocorp CWE-532
critical
9.8
2018-07-11 CVE-2018-0042 Information Exposure Through Log Files vulnerability in Juniper Contrail Service Orchestration
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
network
low complexity
juniper CWE-532
critical
9.8
2018-07-10 CVE-2018-2440 Information Exposure Through Log Files vulnerability in SAP Dynamic Authorization Management 7.7/8.5
Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
local
low complexity
sap CWE-532
4.4