Vulnerabilities (CVE)

Filtered by CWE-200
Total 7102 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-13246 1 Google 1 Android 2018-03-01 5.0 MEDIUM 7.5 HIGH
A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.
CVE-2017-13243 1 Google 1 Android 2018-03-01 5.0 MEDIUM 7.5 HIGH
A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991.
CVE-2018-6610 1 Jlike Project 1 Jlike 2018-03-01 5.0 MEDIUM 7.5 HIGH
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
CVE-2018-6460 1 Anchorfree 1 Hotspot Shield 2018-02-28 5.0 MEDIUM 7.5 HIGH
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.
CVE-2018-1192 1 Pivotal Software 4 Cloud Foundry Cf-deployment, Cloud Foundry Cf-release, Cloud Foundry Uaa and 1 more 2018-02-28 6.5 MEDIUM 8.8 HIGH
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the SessionID is logged in audit event logs. An attacker can use the SessionID to impersonate a logged-in user.
CVE-2017-1785 1 Ibm 1 Api Connect 2018-02-26 4.0 MEDIUM 4.3 MEDIUM
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.
CVE-2013-4317 1 Apache 1 Cloudstack 2018-02-26 4.0 MEDIUM 4.3 MEDIUM
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
CVE-2017-8980 1 Hp 1 Intelligent Management Center 2018-02-26 5.0 MEDIUM 7.5 HIGH
A Remote Disclosure of Information vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
CVE-2012-3331 1 Ibm 1 Sametime 2018-02-22 5.0 MEDIUM 5.3 MEDIUM
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.
CVE-2015-5310 1 Google 1 Android 2018-02-22 3.3 LOW 4.3 MEDIUM
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (ignored packets) via a WNM Sleep Mode response.
CVE-2017-1000250 1 Bluez 1 Bluez 2018-02-17 3.3 LOW 6.5 MEDIUM
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
CVE-2018-6008 1 Joomlatag 1 Jtag Members Directory 2018-02-15 5.0 MEDIUM 7.5 HIGH
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
CVE-2016-0312 1 Ibm 1 Tririga Application Platform 2018-02-14 5.0 MEDIUM 7.5 HIGH
IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. IBM X-Force ID: 111486.
CVE-2014-9970 1 Jasypt Project 1 Jasypt 2018-02-14 5.0 MEDIUM 7.5 HIGH
jasypt before 1.9.2 allows a timing attack against the password hash comparison.
CVE-2018-6014 1 Subsonic 1 Subsonic 2018-02-13 4.3 MEDIUM 6.5 MEDIUM
Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a web site loaded with a SWF file created specifically to steal user data.
CVE-2018-5319 1 Ravpower 1 Filehub Firmware 2018-02-12 5.0 MEDIUM 7.5 HIGH
RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.
CVE-2018-6015 1 Icegram 1 Email Subscribers \& Newsletters 2018-02-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
CVE-2017-1681 1 Ibm 1 Liberty 2018-02-10 2.1 LOW 3.3 LOW
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.
CVE-2017-1000505 1 Jenkins 1 Script Security 2018-02-09 4.0 MEDIUM 6.5 MEDIUM
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.
CVE-2017-2744 1 Hp 1 Support Assistant 2018-02-09 2.1 LOW 5.5 MEDIUM
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.