Total
7102 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-3895 | 1 Google | 1 Android | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 29983260. | |||||
CVE-2016-4719 | 1 Apple | 2 Iphone Os, Watchos | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application. | |||||
CVE-2016-4749 | 1 Apple | 1 Iphone Os | 2017-08-13 | 2.1 LOW | 3.3 LOW |
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file. | |||||
CVE-2016-4740 | 1 Apple | 1 Iphone Os | 2017-08-13 | 1.9 LOW | 2.9 LOW |
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2017-0220 | 1 Microsoft | 3 Windows 7, Windows Server 2008, Windows Server 2012 | 2017-08-13 | 1.9 LOW | 4.7 MEDIUM |
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0258, and CVE-2017-0259. | |||||
CVE-2016-4746 | 1 Apple | 1 Iphone Os | 2017-08-13 | 5.0 MEDIUM | 5.3 MEDIUM |
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction. | |||||
CVE-2016-3892 | 1 Google | 1 Android | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28760543 and Qualcomm internal bug CR1024197. | |||||
CVE-2016-6644 | 1 Emc | 1 Documentum D2 | 2017-08-13 | 5.0 MEDIUM | 5.3 MEDIUM |
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value. | |||||
CVE-2016-4620 | 1 Apple | 1 Iphone Os | 2017-08-13 | 4.3 MEDIUM | 3.3 LOW |
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app. | |||||
CVE-2016-3894 | 1 Google | 1 Android | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29618014 and Qualcomm internal bug CR1042033. | |||||
CVE-2017-0245 | 1 Microsoft | 3 Windows 7, Windows Server 2008, Windows Server 2012 | 2017-08-13 | 1.9 LOW | 4.7 MEDIUM |
The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to execute a specially crafted application to obtain kernel information, aka "Win32k Information Disclosure Vulnerability." | |||||
CVE-2016-3896 | 1 Google | 1 Android | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attackers to obtain sensitive EmailAccountCacheProvider information via a crafted application, aka internal bug 29767043. | |||||
CVE-2016-3897 | 1 Google | 1 Android | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 includes a password in the return value of a toString method call, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25624963. | |||||
CVE-2017-0259 | 1 Microsoft | 5 Windows 10, Windows 8.1, Windows Rt 8.1 and 2 more | 2017-08-13 | 1.9 LOW | 4.7 MEDIUM |
The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0220, and CVE-2017-0258. | |||||
CVE-2016-4306 | 1 Kaspersky | 1 Total Security | 2017-08-13 | 2.1 LOW | 5.5 MEDIUM |
Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability. | |||||
CVE-2016-3893 | 1 Google | 1 Android | 2017-08-13 | 4.3 MEDIUM | 5.5 MEDIUM |
The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P devices does not properly copy firmware data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29512527 and Qualcomm internal bug CR856400. | |||||
CVE-2016-1473 | 1 Cisco | 1 Small Business 220 Series Smart Plus Switches | 2017-08-13 | 10.0 HIGH | 9.8 CRITICAL |
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216. | |||||
CVE-2016-4747 | 1 Apple | 1 Iphone Os | 2017-08-13 | 4.3 MEDIUM | 3.7 LOW |
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors. | |||||
CVE-2016-6936 | 3 Adobe, Apple, Microsoft | 3 Air Sdk \& Compiler, Mac Os X, Windows | 2017-08-13 | 5.0 MEDIUM | 7.5 HIGH |
Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attackers to obtain sensitive information by leveraging access to a network over which analytics data is sent. | |||||
CVE-2017-8840 | 1 Peplink | 12 1350hw2 Firmware, 2500 Firmware, 380hw6 Firmware and 9 more | 2017-08-13 | 5.0 MEDIUM | 5.3 MEDIUM |
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid. |