Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-7846 1 Huawei 14 Ar1200, Ar1200 Firmware, Ar200 and 11 more 2017-10-10 2.1 LOW 4.6 MEDIUM
Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.
CVE-2017-14775 1 Laravel 1 Laravel 2017-10-10 4.3 MEDIUM 5.9 MEDIUM
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
CVE-2015-0238 1 Redhat 1 Openshift 2017-10-10 2.1 LOW 3.3 LOW
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.
CVE-2015-1027 1 Percona 2 Toolkit, Xtrabackup 2017-10-10 4.3 MEDIUM 5.9 MEDIUM
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.
CVE-2014-2029 1 Percona 1 Toolkit 2017-10-10 6.8 MEDIUM 8.1 HIGH
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.
CVE-1999-1136 1 Hp 2 Hp-ux, Mpe Ix 2017-10-09 4.6 MEDIUM N/A
Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.
CVE-2000-0876 1 Texas Imperial Software 2 Wftpd, Wftpd Pro 2017-10-09 5.0 MEDIUM N/A
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.
CVE-2017-9794 1 Apache 1 Geode 2017-10-06 4.0 MEDIUM 4.3 MEDIUM
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view.
CVE-2017-14941 1 Jaspersoft 1 Jasperreports 2017-10-06 4.0 MEDIUM 6.5 MEDIUM
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.
CVE-2017-14954 1 Linux 1 Linux Kernel 2017-10-06 2.1 LOW 5.5 MEDIUM
The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.
CVE-2017-13991 1 Hp 2 Arcsight Enterprise Security Manager, Arcsight Enterprise Security Manager Express 2017-10-05 5.0 MEDIUM 5.3 MEDIUM
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
CVE-2017-13990 1 Hp 2 Arcsight Enterprise Security Manager, Arcsight Enterprise Security Manager Express 2017-10-05 5.0 MEDIUM 5.3 MEDIUM
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
CVE-2015-9231 1 Iterm2 1 Iterm2 2017-10-05 5.0 MEDIUM 7.5 HIGH
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0.0 (and unreleased 2.9.x versions such as 2.9.20150717) that resulted in a potential information disclosure. In an attempt to see whether the text under the cursor (or selected text) was a URL, the text would be sent as an unencrypted DNS query. This has the potential to result in passwords and other sensitive information being sent in cleartext without the user being aware.
CVE-2015-4071 1 Helpdesk Pro Project 1 Helpdesk Pro 2017-10-05 5.0 MEDIUM 5.3 MEDIUM
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.
CVE-2017-14653 1 Asp4cms 1 Aspcms 2017-10-05 4.0 MEDIUM 6.5 MEDIUM
member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.
CVE-2017-9393 1 Ca 2 Identity Manager, Identity Manager Virtual Appliance 2017-10-05 5.0 MEDIUM 9.8 CRITICAL
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
CVE-2015-1849 1 Redhat 1 Jboss Enterprise Application Platform 2017-10-04 4.3 MEDIUM 5.9 MEDIUM
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
CVE-2015-5284 1 Freeipa 1 Freeipa 2017-10-04 5.0 MEDIUM 9.8 CRITICAL
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
CVE-2017-14680 1 Zkteco 1 Zktime Web 2017-10-03 5.0 MEDIUM 7.5 HIGH
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
CVE-2017-1002100 1 Kubernetes 1 Kubernetes 2017-09-29 4.0 MEDIUM 6.5 MEDIUM
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.