CWE-200
10,881 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,881)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nortel 9Business Communications Manager Centrex Ip Client ManagerCentrex Ip Element Manager+6 moreApr 23, 2026 Oct 23, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID num...Show more |
1Nortel 9Business Communications Manager Centrex Ip Client ManagerCentrex Ip Element Manager+6 moreApr 23, 2026 Oct 23, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical e...Show more |
The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space. |
2Gnome Mozilla3Firefox Gnome VfsSeamonkeyApr 23, 2026 Oct 21, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by...Show more |
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, w...Show more |
2Bea Oracle5Tuxedo Weblogic IntegrationWeblogic Portal+2 moreApr 23, 2026 Oct 18, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind,...Show more |
1Symantec 1Altiris Deployment Solution Apr 23, 2026 Oct 18, 2007 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solut...Show more |
Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information....Show more |
Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service", aka PSIRT-1255024833. NOTE: as of 20071016, the only disclosure is a...Show more |
Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS command" involving "two different methods"...Show more |
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not...Show more |
Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file. |
CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files. |
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-mid...Show more |
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-mid...Show more |
1Broadcom 1Etrust Integrated Threat Management Apr 23, 2026 Oct 13, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 stores sensitive user information in log files with predictable names, which allows remote attackers to obtain this information via unspecified vectors. |
Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php. |
2Javaatwork Scottmanktelow2Myftpuploader Module StrideApr 23, 2026 Oct 12, 2007 N/A· v4 N/A· v3 7.8 HIGH· v2 include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow remote attackers to gain unauthorized access to the FTP server being used...Show more |
The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might allow remote attackers to obtain informatio...Show more |
Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information. |