Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2016-06-19 CVE-2016-1183 Permissions, Privileges, and Access Controls vulnerability in Nttdata Terasoluna Server Framework for Java web
NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.
network
high complexity
nttdata CWE-264
3.7
2016-06-10 CVE-2016-5233 Information Exposure vulnerability in Huawei Mate 8 Firmware
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors involving improper security status verification, aka HWPSIRT-2015-12007.
network
high complexity
huawei CWE-200
3.7
2016-06-10 CVE-2016-4527 Credentials Management vulnerability in ABB Pcm600 2.6
ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
abb CWE-255
3.3
2016-06-10 CVE-2016-4516 Information Exposure vulnerability in ABB Pcm600 2.6
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
abb CWE-200
3.3
2016-06-10 CVE-2016-4511 Cryptographic Issues vulnerability in ABB Pcm600 2.6
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.
local
low complexity
abb CWE-310
2.8
2016-06-08 CVE-2016-3711 Information Exposure vulnerability in Redhat Openshift and Openshift Origin
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
local
low complexity
redhat CWE-200
3.3
2016-06-05 CVE-2016-1212 Path Traversal vulnerability in Futomi MP Form Mail CGI 3.2.3
Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
network
low complexity
futomi CWE-22
2.7
2016-05-23 CVE-2016-4486 Information Exposure vulnerability in multiple products
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
local
low complexity
novell canonical linux CWE-200
3.3
2016-05-20 CVE-2016-1852 Information Exposure vulnerability in Apple Iphone OS
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
low complexity
apple CWE-200
2.4
2016-05-20 CVE-2016-1849 Information Exposure vulnerability in Apple Safari
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
local
low complexity
apple CWE-200
3.3