Filtered by CWE-200
Total 9579 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-6808 1 Citrix 4 Netscaler Application Delivery Controller, Netscaler Application Delivery Controller Firmware, Netscaler Gateway and 1 more 2024-11-21 N/A
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.
CVE-2018-6806 1 Marked 2 Project 1 Marked 2 2024-11-21 6.5 Medium
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.
CVE-2018-6790 2 Kde, Redhat 2 Plasma-workspace, Enterprise Linux 2024-11-21 N/A
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.
CVE-2018-6672 1 Mcafee 1 Epolicy Orchestrator 2024-11-21 N/A
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.
CVE-2018-6610 1 Jlike Project 1 Jlike 2024-11-21 N/A
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
CVE-2018-6608 1 Opera 1 Opera Browser 2024-11-21 N/A
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
CVE-2018-6596 2 Debian, Django-anymail Project 2 Debian Linux, Django-anymail 2024-11-21 N/A
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
CVE-2018-6591 1 Conversejs 1 Converse.js 2024-11-21 N/A
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.
CVE-2018-6559 2 Canonical, Linux 2 Ubuntu Linux, Linux Kernel 2024-11-21 N/A
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
CVE-2018-6526 1 Mantisbt 1 Mantisbt 2024-11-21 N/A
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.
CVE-2018-6487 1 Microfocus 1 Universal Cmdb Foundation Software 2024-11-21 N/A
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.
CVE-2018-6470 2 Apple, Nibbleblog 2 Macos, Nibbleblog 2024-11-21 N/A
Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
CVE-2018-6460 1 Anchorfree 1 Hotspot Shield 2024-11-21 N/A
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.
CVE-2018-6412 1 Linux 1 Linux Kernel 2024-11-21 N/A
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
CVE-2018-6293 1 Hyland 1 Saperion Web Client 2024-11-21 N/A
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
CVE-2018-6266 2 Microsoft, Nvidia 2 Windows, Geforce Experience 2024-11-21 N/A
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
CVE-2018-6262 1 Nvidia 1 Geforce Experience 2024-11-21 N/A
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.
CVE-2018-6260 1 Nvidia 1 Gpu Driver 2024-11-21 N/A
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This is not a network or remote attack vector.
CVE-2018-6259 1 Nvidia 1 Geforce Experience 2024-11-21 N/A
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possible.
CVE-2018-6254 1 Google 1 Android 2024-11-21 N/A
In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference: N-CVE-2018-6254.