Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-209
Total 235 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-8161 2 Debian, Postgresql 2 Debian Linux, Postgresql 2020-01-31 4.0 MEDIUM 4.3 MEDIUM
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2019-4636 1 Ibm 1 Security Secret Server 2020-01-30 4.0 MEDIUM 2.7 LOW
IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013.
CVE-2020-7231 1 Evoko 1 Home 2020-01-28 5.0 MEDIUM 5.3 MEDIUM
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
CVE-2019-16768 1 Sylius 1 Sylius 2019-12-17 4.0 MEDIUM 4.3 MEDIUM
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may leak and be visible to the customer. A validation message with the exception details will be presented to the user when one will try to log into the shop. This has been patched in versions 1.3.14, 1.4.10, 1.5.7, and 1.6.3.
CVE-2013-6879 1 Miwisoft 1 Mijosearch 2019-12-04 5.0 MEDIUM 5.3 MEDIUM
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.
CVE-2019-5483 1 Senecajs 1 Seneca 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
CVE-2019-4512 1 Ibm 10 Control Desk, Maximo Asset Management, Maximo For Aviation and 7 more 2019-10-09 4.0 MEDIUM 4.3 MEDIUM
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
CVE-2018-8042 1 Apache 1 Ambari 2019-10-02 4.3 MEDIUM 8.1 HIGH
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
CVE-2017-1370 1 Ibm 1 Jazz Reporting Service 2019-10-02 4.0 MEDIUM 4.9 MEDIUM
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
CVE-2018-11325 1 Joomla 1 Joomla\! 2019-10-02 5.0 MEDIUM 9.8 CRITICAL
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
CVE-2018-2379 1 Sap 1 Hana Extend Application Services 2019-10-02 4.0 MEDIUM 6.5 MEDIUM
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
CVE-2018-17961 4 Artifex, Canonical, Debian and 1 more 9 Ghostscript, Ubuntu Linux, Debian Linux and 6 more 2019-10-02 6.8 MEDIUM 8.6 HIGH
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
CVE-2018-14925 1 Matera 1 Banco 2019-10-02 7.5 HIGH 9.8 CRITICAL
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
CVE-2019-15032 1 Pydio 1 Pydio 2019-09-19 5.0 MEDIUM 5.3 MEDIUM
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.
CVE-2019-11662 1 Microfocus 1 Service Manager 2019-09-19 4.0 MEDIUM 4.3 MEDIUM
Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited in some special cases to allow information exposure through an error message.