Vulnerabilities (CVE)

Filtered by CWE-200
Total 8189 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1941 1 Ibm 1 Tivoli Storage Manager Fastback 2025-04-12 7.8 HIGH N/A
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.
CVE-2014-2869 1 Paperthin 1 Commonspot Content Server 2025-04-12 5.0 MEDIUM N/A
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL server, e-mail address, and IP address information.
CVE-2015-4980 1 Ibm 1 Websphere Commerce 2025-04-12 4.0 MEDIUM N/A
Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.
CVE-2015-5310 1 Google 1 Android 2025-04-12 3.3 LOW 4.3 MEDIUM
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (ignored packets) via a WNM Sleep Mode response.
CVE-2016-2500 1 Google 1 Android 2025-04-12 4.3 MEDIUM 5.5 MEDIUM
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 19285814.
CVE-2015-8335 1 Huawei 1 Vcn500 2025-04-12 4.0 MEDIUM 6.5 MEDIUM
Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.
CVE-2016-6537 1 Aver 2 Eh6108h\+, Eh6108h\+ Firmware 2025-04-12 5.0 MEDIUM 7.5 HIGH
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sensitive information by reading these strings.
CVE-2015-6057 1 Microsoft 1 Edge 2025-04-12 5.0 MEDIUM N/A
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability."
CVE-2015-8090 1 Tibco 1 Loglogic Unity 2025-04-12 4.0 MEDIUM N/A
The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.
CVE-2016-2957 1 Ibm 1 Connections 2025-04-12 4.0 MEDIUM 4.3 MEDIUM
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
CVE-2015-3780 1 Apple 1 Mac Os X 2025-04-12 4.3 MEDIUM N/A
The Bluetooth subsystem in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
CVE-2014-4311 1 Epicor 1 Epicor Enterprise 2025-04-12 5.0 MEDIUM N/A
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings page.
CVE-2013-4279 1 Imapsync Project 1 Imapsync 2025-04-12 5.0 MEDIUM N/A
imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.
CVE-2015-0758 1 Cisco 1 Unified Meetingplace 2025-04-12 4.0 MEDIUM N/A
The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCus97452.
CVE-2014-3852 1 Pyplate 1 Pyplate 2025-04-12 5.0 MEDIUM N/A
Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVE-2015-1901 1 Ibm 1 Infosphere Information Server 2025-04-12 1.9 LOW N/A
The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.
CVE-2016-1185 1 Cybozu 1 Kintone 2025-04-12 2.6 LOW 2.5 LOW
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.
CVE-2016-1378 1 Cisco 1 Ios 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591.
CVE-2014-1908 1 Videowhisper 1 Videowhisper Live Streaming Integration 2025-04-12 5.0 MEDIUM N/A
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
CVE-2016-2940 1 Ibm 1 Bigfix Remote Control 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.