Vulnerabilities (CVE)

Filtered by CWE-200
Total 7896 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-2078 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts.
CVE-2014-1686 1 Mediawiki 1 Mediawiki 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
CVE-2014-10388 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
CVE-2014-10374 1 Fitbit 2 Charge 2, Charge 2 Firmware 2024-11-21 3.3 LOW 6.5 MEDIUM
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without a user-accessible anonymization feature. The devices, such as Charge 2, transmit Bluetooth Low Energy (BLE) advertising packets with a TxAdd flag indicating random addresses, but the addresses remain constant. If devices come within BLE range at one or more locations where an adversary has set up passive sniffing, the adversary can determine whether the same device has entered one of these locations.
CVE-2014-10079 1 Vembu 1 Storegrid 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.
CVE-2014-10076 1 Wp-db-backup Project 1 Wp-db-backup 2024-11-21 5.0 MEDIUM 7.5 HIGH
The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
CVE-2014-10062 1 Qualcomm 56 Mdm9206, Mdm9206 Firmware, Mdm9607 and 53 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, and SDX20, LocationService is being exported, which is a way for a service to expose its methods to other services. This makes it possible for any other services to import LocationService and call into the exposed method for bringing up a data connection.
CVE-2014-10055 1 Qualcomm 4 Sd 400, Sd 400 Firmware, Sd 800 and 1 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected contents if HLOS doesn't request for security restoration for OCMEM xPU's.
CVE-2014-10047 1 Qualcomm 4 Sd 400, Sd 400 Firmware, Sd 800 and 1 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption key to crypto engine, information leak could occur.
CVE-2014-0912 1 Ibm 2 Sterling B2b Integrator, Sterling File Gateway 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
CVE-2014-0882 1 Ibm 16 Flex System Manager 7955, Flex System Manager 8731, Flex System X220 and 13 more 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.
CVE-2014-0872 1 Ibm 1 Security Key Lifecycle Manager 2024-11-21 1.5 LOW 4.1 MEDIUM
The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow local users to obtain sensitive information by leveraging root access. IBM X-Force ID: 90988.
CVE-2014-0242 1 Modwsgi 1 Mod Wsgi 2024-11-21 4.3 MEDIUM 7.5 HIGH
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
CVE-2013-7435 1 Evergreen-ils 1 Evergreen 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
CVE-2013-7203 1 Gitolite 1 Gitolite 2024-11-21 2.1 LOW 5.5 MEDIUM
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
CVE-2013-7089 3 Clamav, Debian, Fedoraproject 3 Clamav, Debian Linux, Fedora 2024-11-21 5.0 MEDIUM 7.5 HIGH
ClamAV before 0.97.7: dbg_printhex possible information leak
CVE-2013-6681 1 Mapway 1 Tube Map 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability
CVE-2013-6455 1 Mediawiki 1 Mediawiki 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.
CVE-2013-5687 1 Aicorporation 1 Risknet Acquirer 2024-11-21 5.0 MEDIUM 7.5 HIGH
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
CVE-2013-4868 1 Karotz 1 Api 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Karotz API 12.07.19.00: Session Token Information Disclosure