← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1073.
1Rust Lang
1Rust
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is:...Show more
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait implementation for std::collections::vec_deque::Iter. The attack vector is: The program needs to invoke debug printing for iterator over an empty VecDeque. The fixed version is: 1.30.0, nightly versions after commit b85e4cc8fadaabd41da5b9645c08c68b8f89908d.Show less
1Fitbit
1Charge 2 Firmware
Nov 21, 2024
Jul 15, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without a user-accessible ano...Show more
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without a user-accessible anonymization feature. The devices, such as Charge 2, transmit Bluetooth Low Energy (BLE) advertising packets with a TxAdd flag indicating random addresses, but the addresses remain constant. If devices come within BLE range at one or more locations where an adversary has set up passive sniffing, the adversary can determine whether the same device has entered one of these locations.Show less
1Gnu
1Glibc
Jun 17, 2026
Jul 15, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-...Show more
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Show less
1Ibm
1Jazz For Service Management
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header o...Show more
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-force ID: 159032.Show less
1Juniper
1Junos
Jun 17, 2026
Jul 11, 2019
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has high priority. This rule is meant for reserved multicast addresses 224.0.0...Show more
On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has high priority. This rule is meant for reserved multicast addresses 224.0.0.x, but incorrectly matches on 224.x.x.x. Due to this bug, when a firewall filter is applied on the loopback interface, other firewall filters might stop working for multicast traffic. The command 'show firewall filter' can be used to confirm whether the filter is working. This issue only affects the EX4300 switch. No other products or platforms are affected by this vulnerability. This issue affects: Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D51, 14.1X53-D115 on EX4300 Series; 17.1 versions prior to 17.1R3 on EX4300 Series; 17.2 versions prior to 17.2R3-S2 on EX4300 Series; 17.3 versions prior to 17.3R3-S3 on EX4300 Series; 17.4 versions prior to 17.4R2-S5, 17.4R3 on EX4300 Series; 18.1 versions prior to 18.1R3-S1 on EX4300 Series; 18.2 versions prior to 18.2R2 on EX4300 Series; 18.3 versions prior to 18.3R2 on EX4300 Series.Show less
1Ibm
1Security Identity Manager Virtual Appliance
Nov 21, 2024
Jul 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153749.
1Pivotal Software
1Cloud Foundry Uaa Release
Jun 17, 2026
Jul 11, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all ot...Show more
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.Show less
1Damicms
1Damicms
Nov 21, 2024
Jul 10, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
1Hp
13par Service Processor Firmware
Jun 17, 2026
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
9.7 HIGH· v2
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for...Show more
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.Show less
1Invoxia
1Nvx220 Firmware
Nov 21, 2024
Jul 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.
1Redhat
1Virt Bootstrap
Jun 17, 2026
Jul 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
3Fedoraproject
LibosinfoRedhat
6Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+3 more
Jun 17, 2026
Jul 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
1Freebsd
1Freebsd
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack m...Show more
In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.Show less
1Odoo
1Odoo
Nov 21, 2024
Jul 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local...Show more
Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.Show less
1Cloudera
1Data Science Workbench
Nov 21, 2024
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.
1Redhat
2Enterprise Linux
Virt Manager
Jun 17, 2026
Jul 3, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking...Show more
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.Show less
1Blipcare
1Wi Fi Blood Pressure Monitor Firmware
Nov 21, 2024
Jul 2, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP proto...Show more
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and have Internet access. This device acts as a Wireless Blood pressure monitor and is used to measure blood pressure levels of a person. This allows an attacker who is connected to the Blipcare's device wireless network to easily sniff these values using a MITM attack.Show less
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
1Ibm
1Spectrum Protect
Jun 17, 2026
Jul 2, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.