Vulnerabilities (CVE)

Filtered by CWE-200
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4166 2 Gnome, Redhat 5 Evolution, Evolution Data Server, Enterprise Linux Desktop and 2 more 2020-02-10 5.0 MEDIUM 7.5 HIGH
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
CVE-2013-0291 1 Imagely 1 Nextgen Gallery 2020-02-06 5.0 MEDIUM 7.5 HIGH
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
CVE-2013-2674 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2020-02-05 5.0 MEDIUM 7.5 HIGH
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.
CVE-2016-4676 1 Apple 2 Mac Os X, Safari 2020-02-05 5.0 MEDIUM 7.5 HIGH
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
CVE-2011-4088 3 Abrt Project, Fedoraproject, Redhat 5 Abrt, Fedora, Enterprise Linux Desktop and 2 more 2020-02-05 5.0 MEDIUM 7.5 HIGH
ABRT might allow attackers to obtain sensitive information from crash reports.
CVE-2011-4937 1 Joomla 1 Joomla\! 2020-02-05 5.0 MEDIUM 7.5 HIGH
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
CVE-2013-2499 1 Simplehrm 1 Simplehrm 2020-01-30 5.0 MEDIUM 7.5 HIGH
SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.
CVE-2018-16269 1 Samsung 20 Galaxy Gear, Galaxy Gear Firmware, Gear 2 and 17 more 2020-01-30 5.0 MEDIUM 7.5 HIGH
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
CVE-2019-15583 1 Gitlab 1 Gitlab 2020-01-29 5.0 MEDIUM 7.5 HIGH
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.
CVE-2013-1594 1 Vivotek 2 Pt7135, Pt7135 Firmware 2020-01-28 5.0 MEDIUM 7.5 HIGH
An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.
CVE-2011-3613 1 Vanillaforums 1 Vanilla 2020-01-28 5.0 MEDIUM 7.5 HIGH
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
CVE-2012-4420 1 Oracle 1 Jdk 2020-01-14 5.0 MEDIUM 7.5 HIGH
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.
CVE-2016-4913 4 Canonical, Linux, Novell and 1 more 6 Ubuntu Linux, Linux Kernel, Suse Linux Enterprise Debuginfo and 3 more 2019-12-27 7.2 HIGH 7.8 HIGH
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
CVE-2019-8567 1 Apple 1 Iphone Os 2019-12-20 5.0 MEDIUM 7.5 HIGH
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.2. A device may be passively tracked by its WiFi MAC address.
CVE-2019-8620 1 Apple 3 Iphone Os, Tvos, Watchos 2019-12-20 5.0 MEDIUM 7.5 HIGH
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A device may be passively tracked by its WiFi MAC address.
CVE-2016-5409 1 Redhat 1 Openshift 2019-12-17 5.0 MEDIUM 7.5 HIGH
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
CVE-2014-0242 1 Modwsgi 1 Mod Wsgi 2019-12-17 4.3 MEDIUM 7.5 HIGH
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
CVE-2019-0405 1 Sap 1 Enable Now 2019-12-17 5.0 MEDIUM 7.5 HIGH
SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information Disclosure.
CVE-2019-1489 1 Microsoft 1 Windows Xp 2019-12-12 5.0 MEDIUM 7.5 HIGH
An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'.
CVE-2014-3526 1 Apache 1 Wicket 2019-12-11 5.0 MEDIUM 7.5 HIGH
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
CVE-2016-5724 1 Cloudera 1 Cdh 2019-12-10 5.0 MEDIUM 7.5 HIGH
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
CVE-2011-2480 2 Freebsd, Netbsd 2 Freebsd, Netbsd 2019-12-10 5.0 MEDIUM 7.5 HIGH
Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.
CVE-2012-5535 2 Fedoraproject, Gnome 2 Fedora, Gnome-system-log 2019-12-09 5.0 MEDIUM 7.5 HIGH
gnome-system-log polkit policy allows arbitrary files on the system to be read
CVE-2012-6079 1 W3-edge 1 Total Cache 2019-12-04 5.0 MEDIUM 7.5 HIGH
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
CVE-2012-6078 1 W3-edge 1 Total Cache 2019-12-04 5.0 MEDIUM 7.5 HIGH
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
CVE-2012-6077 1 W3-edge 1 Total Cache 2019-12-03 5.0 MEDIUM 7.5 HIGH
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
CVE-2015-6495 1 Cloudera 1 Cloudera Manager 2019-12-03 5.0 MEDIUM 7.5 HIGH
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
CVE-2019-5880 1 Google 1 Chrome 2019-12-02 4.3 MEDIUM 7.4 HIGH
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-18460 1 Gitlab 1 Gitlab 2019-11-27 5.0 MEDIUM 7.5 HIGH
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.
CVE-2013-3314 1 Loftek 2 Nexus 543, Nexus 543 Firmware 2019-11-27 5.0 MEDIUM 7.5 HIGH
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.
CVE-2012-1155 4 Debian, Fedoraproject, Moodle and 1 more 4 Debian Linux, Fedora, Moodle and 1 more 2019-11-22 5.0 MEDIUM 7.5 HIGH
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2015-3167 3 Canonical, Debian, Postgresql 3 Ubuntu Linux, Debian Linux, Postgresql 2019-11-22 5.0 MEDIUM 7.5 HIGH
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
CVE-2019-6852 1 Schneider-electric 20 140 Cpu6x, 140 Cpu6x Firmware, 140 Noc 77101 and 17 more 2019-11-22 5.0 MEDIUM 7.5 HIGH
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
CVE-2011-4919 1 Mpack Project 1 Mpack 2019-11-21 5.0 MEDIUM 7.5 HIGH
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
CVE-2013-1817 4 Debian, Fedoraproject, Mediawiki and 1 more 4 Debian Linux, Fedora, Mediawiki and 1 more 2019-11-21 5.0 MEDIUM 7.5 HIGH
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
CVE-2013-7089 3 Clamav, Debian, Fedoraproject 3 Clamav, Debian Linux, Fedora 2019-11-20 5.0 MEDIUM 7.5 HIGH
ClamAV before 0.97.7: dbg_printhex possible information leak
CVE-2019-19022 1 Iterm2 1 Iterm2 2019-11-19 5.0 MEDIUM 7.5 HIGH
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories.
CVE-2017-5803 1 Hp 2 Nonstop Server, Nonstop Server Software 2019-11-19 7.8 HIGH 7.5 HIGH
A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found.
CVE-2011-4972 1 Ckeditor 1 Ckeditor 2019-11-18 5.0 MEDIUM 7.5 HIGH
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
CVE-2018-21026 4 Hitachi, Linux, Microsoft and 1 more 8 Compute Systems Manager, Device Manager, Replication Manager and 5 more 2019-11-18 5.0 MEDIUM 7.5 HIGH
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
CVE-2013-3070 1 Netgear 2 Wndr4700, Wndr4700 Firmware 2019-11-18 5.0 MEDIUM 7.5 HIGH
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
CVE-2019-14365 1 Intercom 1 Intercom 2019-11-14 5.0 MEDIUM 7.5 HIGH
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14366 1 Slack 1 Wp Slacksync 2019-11-14 5.0 MEDIUM 7.5 HIGH
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14367 1 Slack-chat Project 1 Slack-chat 2019-11-14 5.0 MEDIUM 7.5 HIGH
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2010-2450 2 Debian, Shibboleth 2 Debian Linux, Service Provider 2019-11-13 5.0 MEDIUM 7.5 HIGH
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
CVE-2009-5045 2 Debian, Eclipse 2 Debian Linux, Jetty 2019-11-13 5.0 MEDIUM 7.5 HIGH
Dump Servlet information leak in jetty before 6.1.22.
CVE-2013-2261 1 Cryptocat Project 1 Cryptocat 2019-11-05 5.0 MEDIUM 7.5 HIGH
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
CVE-2013-4105 1 Cryptocat Project 1 Cryptocat 2019-11-05 5.0 MEDIUM 7.5 HIGH
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
CVE-2013-2262 1 Cryptocat Project 1 Cryptocat 2019-11-05 5.0 MEDIUM 7.5 HIGH
Cryptocat strophe.js before 2.0.22 has information disclosure
CVE-2013-2600 2 Debian, Miniupnp Project 2 Debian Linux, Miniupnpd 2019-11-04 5.0 MEDIUM 7.5 HIGH
MiniUPnPd has information disclosure use of snprintf()