Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2019-04-03 CVE-2018-4322 Improper Input Validation vulnerability in Apple Iphone OS
This issue was addressed with improved entitlements.
local
low complexity
apple CWE-20
3.3
2019-04-02 CVE-2018-1623 Information Exposure vulnerability in IBM Security Privileged Identity Manager 2.1.1
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-200
3.3
2019-03-27 CVE-2017-2752 7PK - Security Features vulnerability in HP Tommy Hilfiger Th24/7
A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19.
low complexity
hp CWE-254
2.1
2019-03-23 CVE-2019-9942 A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
network
high complexity
symfony debian
3.7
2019-03-21 CVE-2019-9889 Path Traversal vulnerability in Vanillaforums Vanilla
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class.
network
low complexity
vanillaforums CWE-22
2.7
2019-03-21 CVE-2019-8934 Exposure of Resource to Wrong Sphere vulnerability in multiple products
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
local
low complexity
qemu opensuse CWE-668
3.3
2019-03-21 CVE-2018-17502 Information Exposure vulnerability in Thereceptionist the Receptionist for Ipad 4.0.4
The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file.
local
low complexity
thereceptionist CWE-200
3.3
2019-03-21 CVE-2018-15532 Information Exposure vulnerability in HP Synaptics Touchpad Driver 20180606
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.
local
low complexity
hp CWE-200
3.8
2019-03-14 CVE-2018-12224 Information Exposure vulnerability in Intel Graphics Driver
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-200
3.3
2019-03-14 CVE-2018-12222 Out-of-bounds Read vulnerability in Intel Graphics Driver
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause an out of bound memory read via local access.
local
low complexity
intel CWE-125
3.3