← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
4Iphone Os
Mac Os XTvos+1 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1.
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
This issue was addressed by removing additional entitlements. This issue affected versions prior to macOS Mojave 10.14.1.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.1.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A lock screen issue allowed access to photos via Reply With Message on a locked device. This issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.0.1.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.0.1.
1Apple
2Iphone Os
Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of notes deletions. This issue affected versions prior to iOS 12.
1Apple
1Iphone Os
Nov 21, 2024
Apr 3, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Apr 3, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
1Apple
1Cups
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2....Show more
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
An information disclosure issue was addressed by removing the vulnerable code. This issue affected versions prior to macOS High Sierra 10.13.6.
1Gog
1Galaxy
Nov 21, 2024
Apr 2, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can pass a PID and receive information running on it that would usuall...Show more
An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can pass a PID and receive information running on it that would usually only be accessible to the root user.Show less
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Nov 21, 2024
Apr 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
1Ibm
1Api Connect
Nov 21, 2024
Apr 2, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-Force ID: 151636.
1Ibm
1Security Privileged Identity Manager
Nov 21, 2024
Apr 2, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 144410.
1Ibm
1Security Privileged Identity Manager
Nov 21, 2024
Apr 2, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
1Synology
1Drive Server
Nov 21, 2024
Apr 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.
1Synology
1Application Service
Nov 21, 2024
Apr 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the version parameter.