Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-1999 | 1 Ibm | 1 Security Qradar Incident Forensics | 2015-11-09 | 5.0 MEDIUM | N/A |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. | |||||
CVE-2015-1996 | 1 Ibm | 1 Security Qradar Incident Forensics | 2015-11-09 | 2.1 LOW | N/A |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation. | |||||
CVE-2015-1994 | 1 Ibm | 1 Security Qradar Incident Forensics | 2015-11-09 | 5.0 MEDIUM | N/A |
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |||||
CVE-2015-8074 | 1 Google | 1 Android | 2015-11-03 | 5.0 MEDIUM | N/A |
mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than CVE-2015-6611. | |||||
CVE-2015-7859 | 1 Joomla | 1 Joomla\! | 2015-10-30 | 5.0 MEDIUM | N/A |
The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-7900 | 1 Infinite Automation Systems | 1 Mango Automation | 2015-10-28 | 4.3 MEDIUM | N/A |
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger an exception, and then visiting a certain status page. | |||||
CVE-2015-3969 | 1 Janitza | 5 Umg 508, Umg 509, Umg 511 and 2 more | 2015-10-28 | 5.0 MEDIUM | N/A |
Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to UDP port (1) 1234 or (2) 1235. | |||||
CVE-2015-7902 | 1 Infinite Automation Systems | 1 Mango Automation | 2015-10-28 | 5.0 MEDIUM | N/A |
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote attackers to obtain sensitive information via a series of requests. | |||||
CVE-2014-7243 | 1 Lg | 3 L-03e, L-04d, L-09c | 2015-10-28 | 5.0 MEDIUM | N/A |
LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-1165 | 3 Bestpractical, Debian, Fedoraproject | 3 Request Tracker, Debian Linux, Fedora | 2015-10-27 | 5.0 MEDIUM | N/A |
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors. | |||||
CVE-2015-1005 | 1 Ininet Solutions | 1 Scada Web Server | 2015-10-26 | 2.1 LOW | N/A |
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-5661 | 1 Airdroid | 1 Airdroid | 2015-10-19 | 4.3 MEDIUM | N/A |
The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents, which allows attackers to obtain sensitive information via a crafted application. | |||||
CVE-2015-5443 | 1 Hp | 1 3par Service Processor Sp | 2015-10-13 | 4.0 MEDIUM | N/A |
HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2012-6469 | 1 Opera | 1 Opera Browser | 2015-10-08 | 5.0 MEDIUM | N/A |
Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page. | |||||
CVE-2015-5022 | 1 Ibm | 1 B2b Advanced Communications | 2015-10-07 | 4.3 MEDIUM | N/A |
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields. | |||||
CVE-2015-5024 | 1 Ibm | 1 Emptoris Sourcing | 2015-10-07 | 4.0 MEDIUM | N/A |
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors. | |||||
CVE-2015-7314 | 1 Gollum Project | 1 Gollum | 2015-10-07 | 4.3 MEDIUM | N/A |
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. | |||||
CVE-2015-0987 | 1 Omron | 3 Cj2h Plc, Cj2m Plc, Cx-programmer | 2015-10-07 | 5.0 MEDIUM | N/A |
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request. | |||||
CVE-2015-4965 | 1 Ibm | 13 Change And Configuration Management Database, Maximo Asset Management, Maximo Asset Management Essentials and 10 more | 2015-10-06 | 4.0 MEDIUM | N/A |
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to obtain sensitive information by reading a (1) backup or (2) debug application file. | |||||
CVE-2015-0988 | 1 Omron | 1 Cx-programmer | 2015-10-06 | 2.1 LOW | N/A |
Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a file. |