← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Feb 9, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypa...Show more
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 21, 2026
Feb 7, 2008
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
1Ibm
1Aix
Apr 23, 2026
Feb 5, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.
1Kayako
1Supportsuite
Apr 23, 2026
Jan 23, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.
1Mozilla
1Firefox
Apr 23, 2026
Jan 19, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HT...Show more
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.Show less
1X.org
1Xserver
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the fil...Show more
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.Show less
1Keil Software
1Photokorn
Apr 23, 2026
Jan 16, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.
1Phpwebquest
1Phpwebquest
Apr 23, 2026
Jan 12, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE...Show more
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only be an issue in limited environments.Show less
1Wordpress
1Wordpress
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.
1Wordpress
1Wordpress
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
1Layton Technology
1Helpbox
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames.
1Snitz Communications
1Snitz Forums 2000
Apr 23, 2026
Jan 8, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.
12z Project
12z Project
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain year and month parameters, which reveals...Show more
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain year and month parameters, which reveals the path in various error messages.Show less
1Openbiblio
1Openbiblio
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals t...Show more
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals the path in various error messages.Show less
1Openbiblio
1Openbiblio
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
1Google
1Toolbar
Apr 23, 2026
Dec 27, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier...Show more
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier for remote attackers to spoof domain names and trick users into installing malicious button XML files, as demonstrated by presenting www.google.com when the button was downloaded from an arbitrary site through an open redirector on www.google.com.Show less
1Opera
1Opera Browser
Apr 23, 2026
Dec 24, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these conte...Show more
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.Show less
1Apache
1Http Server
Apr 23, 2026
Dec 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (back...Show more
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.Show less
1Hp
1Esupportdiagnostics
Apr 23, 2026
Dec 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via th...Show more
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.Show less
1Php
1Mysql Banner Exchange
Apr 23, 2026
Dec 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.