Vulnerabilities (CVE)

Filtered by CWE-200
Total 7102 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-8970 1 Hp 1 Matrix Operating Environment 2018-03-15 5.0 MEDIUM 5.3 MEDIUM
A remote unauthenticated disclosure of information vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-8978 1 Hp 3 Icewall Mcrp, Icewall Mfa, Icewall Sso 2018-03-15 4.9 MEDIUM 4.6 MEDIUM
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.
CVE-2018-7210 1 Idashboards 1 Idashboards 2018-03-14 5.0 MEDIUM 7.5 HIGH
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=installLicense URI, as demonstrated by intranet IP addresses and names of guest accounts.
CVE-2018-0761 1 Microsoft 2 Windows 7, Windows Server 2008 2018-03-14 2.1 LOW 5.5 MEDIUM
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0760, and CVE-2018-0855.
CVE-2018-0760 1 Microsoft 3 Windows 7, Windows Server 2008, Windows Server 2012 2018-03-14 2.1 LOW 5.5 MEDIUM
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Windows Server 2012 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0761, and CVE-2018-0855.
CVE-2018-0755 1 Microsoft 2 Windows 7, Windows Server 2008 2018-03-14 2.1 LOW 5.5 MEDIUM
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0760, CVE-2018-0761, and CVE-2018-0855.
CVE-2017-6200 1 Sandstorm 1 Sandstorm 2018-03-13 4.0 MEDIUM 6.5 MEDIUM
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) characters in a directory name.
CVE-2016-0351 1 Ibm 1 Security Identity Manager Virtual Appliance 2018-03-13 4.3 MEDIUM 3.7 LOW
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
CVE-2018-7317 1 Christianwebministries 1 Proclaim 2018-03-13 5.0 MEDIUM 7.5 HIGH
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
CVE-2017-13238 1 Google 1 Android 2018-03-13 4.7 MEDIUM 4.2 MEDIUM
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.
CVE-2017-12555 1 Hp 1 Intelligent Management Center 2018-03-13 6.8 MEDIUM 6.5 MEDIUM
A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC) Service Operation Management (SOM) version IMC SOM 7.3 E0501 was found.
CVE-2016-0366 1 Ibm 1 Security Privileged Identity Manager 2018-03-12 4.3 MEDIUM 3.7 LOW
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.
CVE-2016-0367 1 Ibm 1 Security Identity Manager Virtual Appliance 2018-03-12 4.0 MEDIUM 4.3 MEDIUM
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
CVE-2018-7056 1 Steelcase 2 Roomwizard, Roomwizard Firmware 2018-03-12 5.0 MEDIUM 5.3 MEDIUM
RoomWizard before 4.4.x allows remote attackers to obtain potentially sensitive information about IP addresses via /getGroupTimeLineJSON.action.
CVE-2018-7209 1 Idashboards 1 Idashboards 2018-03-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/config.xml URI, as demonstrated by intranet URLs for reports.
CVE-2017-12543 1 Hp 5 Integrated Lights-out, Integrated Lights-out 2 Firmware, Integrated Lights-out 3 Firmware and 2 more 2018-03-12 4.0 MEDIUM 6.5 MEDIUM
A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.
CVE-2018-1392 1 Ibm 1 Financial Transaction Manager 2018-03-12 3.5 LOW 3.1 LOW
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.
CVE-2018-0839 1 Microsoft 2 Edge, Windows 10 2018-03-09 4.3 MEDIUM 4.3 MEDIUM
Microsoft Edge in Microsoft Windows 10 1703 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0763.
CVE-2018-0763 1 Microsoft 2 Edge, Windows 10 2018-03-09 2.6 LOW 3.1 LOW
Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0839.
CVE-2016-0345 1 Ibm 1 Tririga Application Platform 2018-03-09 4.0 MEDIUM 4.3 MEDIUM
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.