Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-0297 1 Keil Software 1 Photokorn 2017-09-28 5.0 MEDIUM N/A
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.
CVE-2008-0598 1 Linux 1 Linux Kernel 2017-09-28 4.9 MEDIUM N/A
Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary.
CVE-2008-0938 1 Sun 1 Solaris 2017-09-28 4.7 MEDIUM N/A
Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.
CVE-2007-5654 1 Litespeed Technologies 1 Litespeed Web Server 2017-09-28 5.0 MEDIUM N/A
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."
CVE-2007-5774 1 Flatnuke3 1 Flatnuke3 2017-09-28 5.0 MEDIUM N/A
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message.
CVE-2007-6476 1 Gf 3xplorer 1 Gf 3xplorer 2017-09-28 5.0 MEDIUM N/A
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.
CVE-2017-1346 1 Ibm 1 Business Process Manager 2017-09-28 1.9 LOW 2.5 LOW
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
CVE-2017-8770 1 Twsz 2 Wifi Repeater, Wifi Repeater Firmware 2017-09-28 7.8 HIGH 7.5 HIGH
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter.
CVE-2017-12157 1 Moodle 1 Moodle 2017-09-28 4.0 MEDIUM 4.3 MEDIUM
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
CVE-2014-8174 1 Redhat 1 Edeploy 2017-09-28 7.5 HIGH 9.8 CRITICAL
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
CVE-2017-0022 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2017-09-27 4.3 MEDIUM 4.3 MEDIUM
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."
CVE-2017-9960 1 Schneider-electric 1 U.motion Builder 2017-09-27 5.0 MEDIUM 5.3 MEDIUM
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
CVE-2014-9616 1 Netsweeper 1 Netsweeper 2017-09-27 5.0 MEDIUM 7.5 HIGH
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page.
CVE-2017-13761 1 Fastly 1 Fastly 2017-09-26 4.0 MEDIUM 6.5 MEDIUM
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses.
CVE-2017-11040 1 Google 1 Android 2017-09-26 4.3 MEDIUM 5.5 MEDIUM
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
CVE-2017-11001 1 Google 1 Android 2017-09-26 4.3 MEDIUM 5.5 MEDIUM
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
CVE-2017-10996 1 Google 1 Android 2017-09-26 7.1 HIGH 5.5 MEDIUM
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access.
CVE-2017-9676 1 Google 1 Android 2017-09-26 2.6 LOW 4.7 MEDIUM
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.
CVE-2015-7880 1 Drupal 1 Drupal 2017-09-26 4.0 MEDIUM 4.3 MEDIUM
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.
CVE-2017-1490 1 Ibm 1 Jazz Reporting Service 2017-09-23 3.5 LOW 5.3 MEDIUM
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.