Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-10911 1 Linux 1 Linux Kernel 2018-09-07 4.9 MEDIUM 6.5 MEDIUM
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
CVE-2018-8341 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2018-09-06 1.9 LOW 4.7 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8348.
CVE-2018-8348 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2018-09-06 1.9 LOW 4.7 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8341.
CVE-2018-8324 1 Microsoft 2 Edge, Windows 10 2018-09-04 4.3 MEDIUM 4.3 MEDIUM
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2018-8325.
CVE-2013-0589 1 Ibm 1 Inotes 2018-09-04 5.0 MEDIUM 7.5 HIGH
IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371.
CVE-2018-13123 1 Onefilecms 1 Onefilecms 2018-09-04 5.0 MEDIUM 9.8 CRITICAL
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.
CVE-2018-9998 1 Open-xchange 1 Open-xchange Appsuite 2018-09-02 4.0 MEDIUM 6.5 MEDIUM
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action to api/tasks.
CVE-2018-12097 1 Liblnk Project 1 Liblnk 2018-08-31 1.9 LOW 5.5 MEDIUM
** DISPUTED ** The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub.
CVE-2018-11729 1 Libfsntfs Project 1 Libfsntfs 2018-08-31 1.9 LOW 5.5 MEDIUM
** DISPUTED ** The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.
CVE-2018-11727 1 Libfsntfs Project 1 Libfsntfs 2018-08-31 1.9 LOW 5.5 MEDIUM
** DISPUTED ** The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.
CVE-2018-11728 1 Libfsntfs Project 1 Libfsntfs 2018-08-31 1.9 LOW 5.5 MEDIUM
** DISPUTED ** The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.
CVE-2018-11731 1 Libfsntfs Project 1 Libfsntfs 2018-08-31 1.9 LOW 5.5 MEDIUM
** DISPUTED ** The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.
CVE-2018-12098 1 Liblnk Project 1 Liblnk 2018-08-31 1.9 LOW 5.5 MEDIUM
** DISPUTED ** The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub.
CVE-2018-12907 1 Rclone 1 Rclone 2018-08-31 5.0 MEDIUM 7.5 HIGH
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
CVE-2018-12921 1 Electroind 2 Gaugetech Nexus, Gaugetech Nexus Firmware 2018-08-31 5.0 MEDIUM 7.5 HIGH
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.
CVE-2018-12927 1 Northernnep 2 Northern Electric \& Power Inverter, Northern Electric \& Power Inverter Firmware 2018-08-30 5.0 MEDIUM 7.5 HIGH
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.
CVE-2018-12926 1 Pharoscontrols 2 Pharos, Pharos Firmware 2018-08-30 5.0 MEDIUM 7.5 HIGH
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.
CVE-2018-12735 1 Saj-electric 1 Saj Solar Inverter 2018-08-30 5.0 MEDIUM 7.5 HIGH
SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inverter_info.htm or english_main.htm URI.
CVE-2018-12990 1 Phpwcms 1 Phpwcms 2018-08-28 5.0 MEDIUM 5.3 MEDIUM
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
CVE-2018-7776 1 Schneider-electric 1 U.motion Builder 2018-08-28 4.3 MEDIUM 4.3 MEDIUM
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.