← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jollytech
1Lobby Track
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker co...Show more
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database.Show less
1Jollytech
1Lobby Track
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploi...Show more
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploit this vulnerability to view the driver's license number and other personal information.Show less
1Jollytech
1Lobby Track
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerabi...Show more
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information.Show less
1Hp
1Synaptics Touchpad Driver
Nov 21, 2024
Mar 21, 2019
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.
1Top Vision
1Cc8800ce Firmware
Nov 21, 2024
Mar 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with userName=admin in a cookie.
1Opensuse
1Yast2 Samba Provision
Nov 21, 2024
Mar 15, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samba-provision, allowing local attackers to read them in the process list
1Ibm
1Rational Engineering Lifecycle Manager
Nov 21, 2024
Mar 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM...Show more
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.Show less
1Intel
1Graphics Driver
Nov 21, 2024
Mar 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and...Show more
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an authenticated user to potentially enable information disclosure via local access.Show less
1Huawei
1Oceanstor Uds Firmware
Nov 21, 2024
Mar 13, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resulting in the deletion of directory files and compromise of system funct...Show more
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resulting in the deletion of directory files and compromise of system functions when loading a patch.Show less
1Mcafee
1Database Security
Jun 17, 2026
Mar 12, 2019
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin...Show more
Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.Show less
1Lexmark
8Cx725h Firmware
Cx820 FirmwareCx825 Firmware+5 more
Nov 21, 2024
Mar 12, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the...Show more
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.Show less
1Ibm
1Api Connect
Nov 21, 2024
Mar 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc....Show more
IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Mar 11, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.
1Cloudfoundry
1Command Line Interface
Jun 17, 2026
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
3.5 LOW· v2
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or al...Show more
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.Show less
1Apache
1Traffic Server
Nov 21, 2024
Mar 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This p...Show more
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.Show less
1Apple
1Iphone Os
Jun 17, 2026
Mar 4, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually c...Show more
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually cleared.Show less
1Mozilla
1Firefox
Nov 21, 2024
Feb 28, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: th...Show more
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.Show less
4Canonical
DebianMozilla+1 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 25, 2025
Feb 28, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts i...Show more
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.Show less
1Ibm
1Bigfix Platform
Jun 17, 2026
Feb 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Fo...Show more
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.Show less
1Ibm
2Spectrum Virtualize Software
Spectrum Virtualize Software For Public Cloud
Nov 21, 2024
Feb 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force...Show more
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.Show less