Total
8278 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4643 | 1 Apple | 3 Apple Tv, Iphone Os, Mac Os | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation. | |||||
CVE-2018-18073 | 4 Artifex, Canonical, Debian and 1 more | 9 Ghostscript, Ubuntu Linux, Debian Linux and 6 more | 2024-02-04 | 4.3 MEDIUM | 6.3 MEDIUM |
Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object. | |||||
CVE-2018-19045 | 1 Keepalived | 1 Keepalived | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information. | |||||
CVE-2018-12374 | 4 Canonical, Debian, Mozilla and 1 more | 7 Ubuntu Linux, Debian Linux, Thunderbird and 4 more | 2024-02-04 | 4.3 MEDIUM | 4.3 MEDIUM |
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9. | |||||
CVE-2018-16969 | 1 Citrix | 1 Sharefile Storagezones Controller | 2024-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. | |||||
CVE-2018-20571 | 1 Damicms | 1 Damicms | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file. | |||||
CVE-2018-15773 | 1 Dell | 1 Data Protection \| Encryption | 2024-02-04 | 4.9 MEDIUM | 4.3 MEDIUM |
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files. | |||||
CVE-2018-1886 | 1 Ibm | 1 Security Access Manager | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021. | |||||
CVE-2018-6259 | 1 Nvidia | 1 Geforce Experience | 2024-02-04 | 1.9 LOW | 2.5 LOW |
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possible. | |||||
CVE-2018-18778 | 1 Acme | 1 Mini-httpd | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
ACME mini_httpd before 1.30 lets remote users read arbitrary files. | |||||
CVE-2018-15964 | 1 Adobe | 1 Coldfusion | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to information disclosure. | |||||
CVE-2015-9269 | 1 Wpmobilepack | 1 Wordpress Mobile Pack | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information because the content of a privately published post is sent in JSON format. | |||||
CVE-2018-17780 | 1 Telegram | 2 Telegram Desktop, Telegram Messenger | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list. | |||||
CVE-2018-14941 | 1 Harmonicinc | 1 Nsg 9000 | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for the /webapp.py URI. | |||||
CVE-2015-5160 | 2 Libvirt, Redhat | 10 Libvirt, Enterprise Linux, Enterprise Linux Desktop and 7 more | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing. | |||||
CVE-2018-13352 | 1 Terra-master | 1 Terramaster Operating System | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directory. | |||||
CVE-2018-1564 | 1 Ibm | 1 Sterling B2b Integrator | 2024-02-04 | 2.1 LOW | 6.7 MEDIUM |
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968. | |||||
CVE-2017-12173 | 2 Fedoraproject, Redhat | 6 Sssd, Enterprise Linux Desktop, Enterprise Linux Server and 3 more | 2024-02-04 | 4.0 MEDIUM | 8.8 HIGH |
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it. | |||||
CVE-2018-8444 | 1 Microsoft | 4 Windows 10, Windows 8.1, Windows Rt 8.1 and 1 more | 2024-02-04 | 4.3 MEDIUM | 5.9 MEDIUM |
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "Windows SMB Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2. | |||||
CVE-2018-8370 | 1 Microsoft | 3 Edge, Windows 10, Windows Server 2016 | 2024-02-04 | 4.3 MEDIUM | 3.1 LOW |
A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. |