CWE-200
10,487 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,487)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Identity Services Engine Nov 21, 2024 Jan 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improp...Show more |
1Ibm 1Financial Transaction Manager Nov 21, 2024 Jan 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552. |
1Qualcomm 28Mdm9607 Firmware Mdm9635m FirmwareMdm9640 Firmware+25 moreNov 21, 2024 Jan 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8...Show more |
Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privileges granted to a session. |
1Microsoft 1Team Foundation Server Jun 17, 2026 Jan 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." This affects Team. |
2Canonical Isc2Bind Ubuntu LinuxJun 17, 2026 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (...Show more |
4Debian FedoraprojectOpensuse+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 15, 2019 N/A· v4 5.2 MEDIUM· v3 2.7 LOW· v2 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that res...Show more |
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authen...Show more |
5Canonical DebianNetapp+2 more21Active Iq Performance Analytics Services Debian LinuxElement Software+18 moreNov 21, 2024 Jan 11, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 a...Show more |
In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing. |
In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation. |
1Apple 4Iphone Os Mac Os XTvos+1 moreNov 21, 2024 Jan 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state han...Show more |
In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic. |
1Apple 3Apple Tv Iphone OsMac OsNov 21, 2024 Jan 11, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by stor...Show more |
1Apple 3Apple Tv Iphone OsMac OsNov 21, 2024 Jan 11, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response val...Show more |
1Cisco 1Identity Services Engine Nov 21, 2024 Jan 10, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of save...Show more |
1Cisco 1Unified Communications Manager Nov 21, 2024 Jan 10, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorr...Show more |
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. |
mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output de...Show more |
1Nec 2Aterm Wf1200cr Firmware Aterm Wg1200cr FirmwareNov 21, 2024 Jan 9, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on the same network segment to obtain information registered on the device...Show more |