Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2016-08-24 CVE-2016-5812 Information Exposure vulnerability in Moxa Oncell G3001 Firmware and Oncell G3100V2 Firmware
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file.
local
low complexity
moxa CWE-200
3.3
2016-08-10 CVE-2013-7458 Information Exposure vulnerability in multiple products
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
local
low complexity
redislabs debian CWE-200
3.3
2016-08-09 CVE-2016-3321 Information Exposure vulnerability in Microsoft Internet Explorer 10/11
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability."
local
high complexity
microsoft CWE-200
2.5
2016-08-08 CVE-2016-2960 Improper Access Control vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
network
high complexity
ibm CWE-284
3.7
2016-08-08 CVE-2016-0380 Permissions, Privileges, and Access Controls vulnerability in IBM Sterling Connect:Direct
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.
local
low complexity
ibm CWE-264
3.3
2016-08-08 CVE-2016-0281 Improper Input Validation vulnerability in IBM AIX and Vios
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
network
high complexity
ibm CWE-20
3.7
2016-08-08 CVE-2016-0266 7PK - Security Features vulnerability in IBM AIX and Vios
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
network
high complexity
ibm CWE-254
3.7
2016-07-22 CVE-2016-6224 Improper Input Validation vulnerability in multiple products
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
ecryptfs canonical CWE-20
3.3
2016-07-22 CVE-2015-8946 Improper Input Validation vulnerability in multiple products
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
canonical ecryptfs CWE-20
3.3
2016-07-22 CVE-2016-4645 Information Exposure vulnerability in Apple mac OS X
CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
apple CWE-200
3.3