← Back
CWE-200

10,881 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,881)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Duplicity Project
1Duplicity
Apr 23, 2026
Oct 4, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its arguments.
1Quicksilver Forums
1Quicksilver Forums
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message.
1Apple
1Safari
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of...Show more
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent window is in a different domain.Show less
1Boesch It
1Simpgb
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php;...Show more
SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php; and (2) download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.Show less
1Elinks
1Elinks
Apr 23, 2026
Sep 21, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that...Show more
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.Show less
1Dibbler
1Dibbler
Apr 23, 2026
Sep 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Dibbler 0.6.0 on Linux uses weak world-writable permissions for unspecified files in /var/lib/dibbler, which has unknown impact and local attack vectors.
1Microsoft
1Isa Server
Apr 23, 2026
Sep 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) vi...Show more
The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.Show less
1Ibm
1Tivoli Storage Manager Client
Apr 23, 2026
Sep 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows...Show more
Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows remote attackers to read a client's data, aka IC53616.Show less
1Wilson Windowware
1Webbatch
Apr 23, 2026
Sep 20, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.
1Firebirdsql
1Firebird
Apr 23, 2026
Sep 4, 2007
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
1Backup Manager
1Backup Manager
Apr 23, 2026
Sep 4, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive informati...Show more
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.Show less
1Cgi Rescue
1Shopping Basket Professional
Apr 23, 2026
Sep 4, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal se...Show more
Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.Show less
1Apache
1Tomcat
Apr 23, 2026
Aug 14, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as ses...Show more
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.Show less
1Apache
1Tomcat
Apr 23, 2026
Aug 14, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be le...Show more
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.Show less
1Apple
1Quicktime
Apr 23, 2026
Jul 15, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.
1Microsoft
1.net Framework
Apr 23, 2026
Jul 10, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and po...Show more
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."Show less
1Mozilla
1Firefox
Apr 23, 2026
Jul 10, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, an...Show more
Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.Show less
1Mozilla
1Firefox
Apr 23, 2026
Jun 6, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.
1Mbedthis Software
1Mbedthis Appweb Http Server
Apr 23, 2026
Jun 4, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-33...Show more
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.Show less
1Psychostats
1Psychostats
Apr 23, 2026
May 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.