← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wefi
1Wefi
Apr 23, 2026
Jul 11, 2008
N/A· v4
N/A· v3
4.7 MEDIUM· v2
WeFi 3.2.1.4.1, when diagnostic mode is enabled, stores (1) WEP, (2) WPA, and (3) WPA2 access-point keys in (a) ClientWeFiLog.dat, (b) ClientWeFiLog.bak, and possibly (c) a certain .inf file under %PROGRAMFILES%\WeFi\Use...Show more
WeFi 3.2.1.4.1, when diagnostic mode is enabled, stores (1) WEP, (2) WPA, and (3) WPA2 access-point keys in (a) ClientWeFiLog.dat, (b) ClientWeFiLog.bak, and possibly (c) a certain .inf file under %PROGRAMFILES%\WeFi\Users\, and uses cleartext for the ClientWeFiLog files, which allows local users to obtain sensitive information by reading these files.Show less
1Wireshark
1Wireshark
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.
2Rpath
Wireshark
2Rpath Linux
Wireshark
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.
2Rpath
Wireshark
2Rpath Linux
Wireshark
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.
1Sun
3Jdk
JreSdk
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information...Show more
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.Show less
1Organic Groups Project
1Organic Groups
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via unspecified vectors.
1Opera
1Opera Browser
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized memory contents by using JavaScript to read a canvas image.
1Fascript
1Faname
Apr 23, 2026
Jul 9, 2008
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error me...Show more
class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error message.Show less
1Mywebland
1Mybloggie
Apr 23, 2026
Jul 9, 2008
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array para...Show more
myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages.Show less
1Microsoft
5Data Engine
Sql ServerSql Server Desktop Engine+2 more
Apr 23, 2026
Jul 8, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon)...Show more
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.Show less
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859...Show more
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.Show less
1Typo3
1Pdf Generator 2 Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.
1Typo3
1Dam Frontend Extension
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
1Linux
1Linux Kernel
Apr 23, 2026
Jun 30, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive i...Show more
arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Jun 30, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary.
1Relative Real Estate Systems
1Relative Real Estate Systems
Apr 23, 2026
Jun 26, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
1Elinestudio
1Site Composer
Apr 23, 2026
Jun 25, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path.
1Otomigenx
1Otomigenx
Apr 23, 2026
Jun 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) library_rss.php and (2) rss.php.
1No Ip
1Dynamic Update Client
Apr 23, 2026
Jun 18, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by readi...Show more
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.Show less
1Menalto
1Gallery
Apr 23, 2026
Jun 16, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."