Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-1580 1 Mozilla 1 Firefox 2016-12-21 5.0 MEDIUM N/A
Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element.
CVE-2015-4503 1 Mozilla 1 Firefox 2016-12-21 5.0 MEDIUM N/A
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.
CVE-2015-4961 1 Ibm 1 Tealeaf Customer Experience 2016-12-21 2.9 LOW 2.6 LOW
IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 does not encrypt connections between internal servers, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
CVE-2015-4980 1 Ibm 1 Websphere Commerce 2016-12-21 4.0 MEDIUM N/A
Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.
CVE-2016-1787 1 Apple 1 Mac Os X Server 2016-12-19 5.0 MEDIUM 5.3 MEDIUM
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
CVE-2016-6852 1 Open-xchange 1 Open-xchange Appsuite 2016-12-16 4.3 MEDIUM 4.3 MEDIUM
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system files or library versions on the middleware server to prepare further attacks.
CVE-2016-6364 1 Cisco 1 Unified Communications Manager 2016-12-12 5.0 MEDIUM 7.5 HIGH
The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka Bug ID CSCux67855.
CVE-2015-5864 1 Apple 1 Mac Os X 2016-12-09 2.1 LOW N/A
IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
CVE-2015-5836 1 Apple 1 Mac Os X 2016-12-09 4.3 MEDIUM N/A
Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.
CVE-2015-5853 1 Apple 1 Mac Os X 2016-12-09 3.3 LOW N/A
AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors.
CVE-2015-5854 1 Apple 1 Mac Os X 2016-12-09 2.1 LOW N/A
The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.
CVE-2015-5865 1 Apple 1 Mac Os X 2016-12-09 4.3 MEDIUM N/A
IOGraphics in Apple OS X before 10.11 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
CVE-2015-5870 1 Apple 1 Mac Os X 2016-12-09 2.1 LOW N/A
The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.
CVE-2015-5878 1 Apple 1 Mac Os X 2016-12-09 2.1 LOW N/A
Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors.
CVE-2015-6328 1 Cisco 1 Prime Collaboration Assurance 2016-12-09 6.8 MEDIUM N/A
The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and read arbitrary files via a crafted URL, aka Bug ID CSCus88380.
CVE-2015-4543 1 Emc 1 Rsa Archer Grc 2016-12-08 4.0 MEDIUM N/A
EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remote authenticated users to obtain sensitive information by reading database fields.
CVE-2015-6843 1 Emc 1 Sourceone Email Supervisor 2016-12-08 5.0 MEDIUM N/A
Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach.
CVE-2015-7032 1 Apple 4 Iwork, Keynote, Numbers and 1 more 2016-12-08 4.3 MEDIUM N/A
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.
CVE-2015-7322 1 Juniper 1 Pulse Connect Secure 2016-12-07 5.0 MEDIUM N/A
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.
CVE-2015-5884 1 Apple 1 Mac Os X 2016-12-07 3.3 LOW N/A
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.