Vulnerabilities (CVE)

Filtered by CWE-200
Total 8218 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-6627 1 Phpmyadmin 1 Phpmyadmin 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2011-2513 1 Redhat 2 Icedtea-web, Icedtea6 2025-04-12 5.0 MEDIUM N/A
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
CVE-2015-3404 1 Certify Project 1 Certify 2025-04-12 4.0 MEDIUM N/A
The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."
CVE-2016-1337 1 Cisco 2 Epc3928, Epc3928 Firmware 2025-04-12 4.3 MEDIUM 8.1 HIGH
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, aka Bug ID CSCux17178.
CVE-2016-2861 1 Ibm 1 Websphere Extreme Scale 2025-04-12 4.3 MEDIUM 3.7 LOW
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
CVE-2016-8100 1 Intel 1 Integrated Performance Primitives 2025-04-12 2.1 LOW 5.5 MEDIUM
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack.
CVE-2014-4721 2 Debian, Php 2 Debian Linux, Php 2025-04-12 2.6 LOW N/A
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.
CVE-2016-9284 1 Exponentcms 1 Exponent Cms 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.
CVE-2016-4646 1 Apple 1 Mac Os X 2025-04-12 4.3 MEDIUM 6.5 MEDIUM
Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted audio file.
CVE-2016-1000214 1 Ruckus 1 Wireless H500 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
Ruckus Wireless H500 web management interface authentication bypass
CVE-2016-0793 2 Microsoft, Redhat 2 Windows, Jboss Wildfly Application Server 2025-04-12 5.0 MEDIUM 7.5 HIGH
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.
CVE-2016-4485 3 Canonical, Linux, Novell 5 Ubuntu Linux, Linux Kernel, Suse Linux Enterprise Debuginfo and 2 more 2025-04-12 5.0 MEDIUM 7.5 HIGH
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
CVE-2016-6344 1 Redhat 1 Jboss Bpm Suite 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
CVE-2015-2209 1 Dlguard 1 Dlguard 2025-04-12 5.0 MEDIUM N/A
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
CVE-2014-8112 1 Fedoraproject 2 389 Directory Server, Fedora 2025-04-12 4.0 MEDIUM N/A
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
CVE-2016-0079 1 Microsoft 1 Windows 10 2025-04-12 2.1 LOW 5.0 MEDIUM
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability."
CVE-2015-3981 1 Sap 1 Netweaver Rfc Sdk 2025-04-12 5.0 MEDIUM N/A
SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.
CVE-2015-6088 1 Microsoft 2 Edge, Internet Explorer 2025-04-12 4.3 MEDIUM N/A
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."
CVE-2015-0211 1 Moodle 1 Moodle 2025-04-12 4.0 MEDIUM N/A
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.
CVE-2014-8035 1 Cisco 1 Webex Meetings Server 2025-04-12 5.0 MEDIUM N/A
The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCuj40247.