← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Esx
Apr 23, 2026
Sep 3, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the proc...Show more
The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 28, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtai...Show more
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Aug 25, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs du...Show more
The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.Show less
1Postfix
1Postfix
Apr 23, 2026
Aug 18, 2008
N/A· v4
N/A· v3
1.9 LOW· v2
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding...Show more
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.Show less
1Vmware
1Virtualcenter
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functi...Show more
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."Show less
1Linux
1Ipsec Tools Racoon Daemon
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Memory leak in racoon/proposal.c in the racoon daemon in ipsec-tools before 0.7.1 allows remote authenticated users to cause a denial of service (memory consumption) via invalid proposals.
1Microsoft
2Windows Nt
Windows Vista
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and al...Show more
Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.Show less
1Microsoft
1Windows Messenger
Apr 23, 2026
Aug 13, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact infor...Show more
An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors.Show less
1Ibm
1Rational Clearquest
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly...Show more
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.Show less
4Canonical
DebianLinux+1 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+4 more
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthd...Show more
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.Show less
1Vtiger
1Vtiger Crm
Apr 23, 2026
Aug 4, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload direct...Show more
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.Show less
1Phpwebgallery
1Phpwebgallery
Apr 23, 2026
Aug 4, 2008
N/A· v4
N/A· v3
4.0 MEDIUM· v2
PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.
1Xrms
1Xrms Crm
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function.
1Avidweb Technologies
1Jobbex Jobsite
Apr 23, 2026
Jul 28, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path in an error message.
1Moodle
1Moodle
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation p...Show more
Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.Show less
1Tuxplanet
1Bilboblog
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error...Show more
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.Show less
1Openbsd
1Openssh
Apr 23, 2026
Jul 22, 2008
N/A· v4
N/A· v3
1.2 LOW· v2
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP ad...Show more
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.Show less
1Apple
1Safari
Apr 23, 2026
Jul 14, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
1Empire Server
1Empire Server
Apr 23, 2026
Jul 14, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed.
1Apple
2Xcode
Xcode Tools
Apr 23, 2026
Jul 14, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the...Show more
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.Show less