Vulnerabilities (CVE)

Filtered by CWE-200
Total 8075 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-2771 1 Websense 2 Triton Ap Email, V-series Appliances 2016-12-03 5.0 MEDIUM N/A
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVE-2015-2762 1 Websense 1 Triton Ap Web 2016-12-03 5.0 MEDIUM N/A
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.
CVE-2015-2335 1 Mybb 1 Mybb 2016-12-03 5.0 MEDIUM N/A
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.
CVE-2015-2214 1 Netcat 1 Netcat 2016-12-03 5.0 MEDIUM N/A
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
CVE-2015-2209 1 Dlguard 1 Dlguard 2016-12-03 5.0 MEDIUM N/A
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
CVE-2015-2121 1 Hp 1 Network Virtualization 2016-12-03 7.8 HIGH N/A
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569.
CVE-2015-1127 1 Apple 1 Safari 2016-12-03 2.1 LOW N/A
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.
CVE-2014-9759 1 Mantisbt 1 Mantisbt 2016-12-03 5.0 MEDIUM 5.3 MEDIUM
Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request.
CVE-2016-8100 1 Intel 1 Integrated Performance Primitives 2016-12-02 2.1 LOW 5.5 MEDIUM
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack.
CVE-2016-7561 1 Fortinet 1 Fortiwlc 2016-12-02 4.0 MEDIUM 7.2 HIGH
Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file.
CVE-2016-7917 1 Linux 1 Linux Kernel 2016-12-02 4.3 MEDIUM 5.0 MEDIUM
The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.
CVE-2016-1852 1 Apple 1 Iphone Os 2016-12-02 2.1 LOW 2.4 LOW
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
CVE-2016-1853 1 Apple 1 Mac Os X 2016-12-02 5.0 MEDIUM 7.5 HIGH
Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.
CVE-2016-3012 1 Ibm 2 Api Connect, Network Path Manager 2016-12-01 5.0 MEDIUM 7.5 HIGH
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
CVE-2016-2025 1 Hp 1 Service Manager 2016-12-01 5.0 MEDIUM 7.5 HIGH
HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components.
CVE-2016-2023 1 Hp 1 Restful Interface Tool 2016-12-01 2.1 LOW 5.5 MEDIUM
HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.
CVE-2016-2015 1 Hp 1 System Management Homepage 2016-12-01 6.6 MEDIUM 7.1 HIGH
HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.
CVE-2016-2013 1 Hp 1 Network Node Manager I 2016-12-01 4.0 MEDIUM 6.5 MEDIUM
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVE-2016-1849 1 Apple 2 Iphone Os, Safari 2016-12-01 2.1 LOW 3.3 LOW
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
CVE-2016-1796 1 Apple 1 Mac Os X 2016-12-01 4.3 MEDIUM 3.3 LOW
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.