Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-4069 | 1 Arcserve | 1 Arcserve Unified Data Protection | 2016-12-05 | 7.8 HIGH | N/A |
The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method. | |||||
CVE-2015-4981 | 1 Ibm | 2 General Parallel File System, Spectrum Scale | 2016-12-05 | 2.1 LOW | N/A |
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors. | |||||
CVE-2015-3448 | 1 Rest-client Project | 1 Rest-client | 2016-12-05 | 2.1 LOW | N/A |
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. | |||||
CVE-2015-3949 | 1 Sinapsi | 2 Esolar Light, Esolar Light Firmware | 2016-12-05 | 2.1 LOW | N/A |
Sinapsi eSolar Light with firmware before 2.0.3970_schsl_2.2.85 allows attackers to discover cleartext passwords by reading the HTML source code of the mail-configuration page. | |||||
CVE-2015-3373 | 1 Amazon Aws Project | 1 Amazon Aws | 2016-12-05 | 5.0 MEDIUM | N/A |
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL. | |||||
CVE-2015-3404 | 1 Certify Project | 1 Certify | 2016-12-05 | 4.0 MEDIUM | N/A |
The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates." | |||||
CVE-2015-2012 | 1 Ibm | 1 Websphere Mq | 2016-12-05 | 2.1 LOW | 4.0 MEDIUM |
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file. | |||||
CVE-2016-2845 | 1 Google | 1 Chrome | 2016-12-02 | 5.0 MEDIUM | 5.3 MEDIUM |
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp. | |||||
CVE-2016-2887 | 2 Ibm, Microsoft | 2 Ims Enterprise Suite, .net Framework | 2016-12-02 | 5.5 MEDIUM | 8.1 HIGH |
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-2940 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 5.0 MEDIUM | 5.3 MEDIUM |
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors. | |||||
CVE-2016-2949 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 2.1 LOW | 3.3 LOW |
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session. | |||||
CVE-2016-2952 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-02 | 4.3 MEDIUM | 3.7 LOW |
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP. | |||||
CVE-2016-3155 | 1 Siemens | 1 Apogee Insight | 2016-12-02 | 3.6 LOW | 3.4 LOW |
Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-3158 | 3 Fedoraproject, Oracle, Xen | 3 Fedora, Vm Server, Xen | 2016-12-02 | 1.7 LOW | 3.8 LOW |
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076. | |||||
CVE-2016-1992 | 1 Hp | 2 Enterprise Security Manager, Enterprise Security Manager Express | 2016-12-02 | 4.0 MEDIUM | 6.5 MEDIUM |
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-1994 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 4.0 MEDIUM | 6.5 MEDIUM |
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-2244 | 1 Hp | 55 A2w75a, A2w76a, A2w77a and 52 more | 2016-12-02 | 5.0 MEDIUM | 5.9 MEDIUM |
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-1780 | 1 Apple | 1 Iphone Os | 2016-12-02 | 4.3 MEDIUM | 4.3 MEDIUM |
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site. | |||||
CVE-2016-1967 | 1 Mozilla | 1 Firefox | 2016-12-02 | 4.3 MEDIUM | 6.5 MEDIUM |
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207. | |||||
CVE-2016-1758 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-02 | 4.3 MEDIUM | 3.3 LOW |
The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app. |