← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Mozilla
2Firefox
Ubuntu Linux
Apr 23, 2026
Mar 21, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive informat...Show more
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.Show less
1Bj Sintay
1Sitex
Apr 23, 2026
Mar 3, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL error.
1Norman
1Norman Sandbox Analyzer
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a phy...Show more
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.Show less
1Dzcp
1Dev!l'z Clanportal
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.
1Mrcgiguy
1Hot Links
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
1Mozilla
1Firefox
Apr 23, 2026
Feb 26, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session...Show more
The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.Show less
3Canonical
DebianMozilla
4Debian Linux
FirefoxSeamonkey+1 more
Apr 23, 2026
Feb 26, 2007
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote a...Show more
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.Show less
1Pearson Education
1Powerschool
Apr 23, 2026
Feb 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported...Show more
Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.Show less
1Lifetype
1Lifetype
Apr 23, 2026
Feb 16, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."
1Headstart Solutions
1Deskpro
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.
1Headstart Solutions
1Deskpro
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.
1Globetrotter
1Mobility Manager
Apr 23, 2026
Jan 29, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or gr...Show more
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots.Show less
1Ezboxx
1Ezboxx Portal System
Apr 23, 2026
Jan 16, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.
1Cisco
1Network Admission Control Manager And Server System Software
Apr 23, 2026
Jan 4, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the sna...Show more
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.Show less
1Phpwcms
1Phpwcms
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in include/inc_lib/, which reveals the path in v...Show more
phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in include/inc_lib/, which reveals the path in various error messages.Show less
1Adobe
2Coldfusion
Jrun
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filena...Show more
Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.Show less
1Obie Website
1Mini Web Shop
Apr 23, 2026
Dec 26, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which rev...Show more
modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP s...Show more
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."Show less
1Tiki
1Tikiwiki Cms/groupware
Apr 23, 2026
Dec 11, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks...Show more
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.Show less
1Aep Networks
1Smartgate Ssl Server
Apr 23, 2026
Nov 4, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directo...Show more
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.Show less