← Back
CWE-200

10,487 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,487)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Identity Services Engine
Nov 21, 2024
Jan 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improp...Show more
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improper handling of confidential information. An attacker could exploit this vulnerability by logging into the web interface on a vulnerable system. An exploit could allow an attacker to obtain confidential information for privileged accounts. This information could then be used to impersonate or negatively impact the privileged account on the affected system.Show less
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Jan 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.
1Qualcomm
28Mdm9607 Firmware
Mdm9635m FirmwareMdm9640 Firmware+25 more
Nov 21, 2024
Jan 18, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8...Show more
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130Show less
1Adobe
1Connect
Nov 21, 2024
Jan 18, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privileges granted to a session.
1Microsoft
1Team Foundation Server
Jun 17, 2026
Jan 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." This affects Team.
2Canonical
Isc
2Bind
Ubuntu Linux
Jun 17, 2026
Jan 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (...Show more
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of "allow-recursion {localhost; localnets;};" if "recursion yes;" is in effect and no values are explicitly set for "allow-query-cache" or "allow-query". However, because of the regression introduced by change #4777, it is possible when "recursion yes;" is in effect and no match list values are provided for "allow-query-cache" or "allow-query" for the setting of "allow-recursion" to inherit a setting of all hosts from the "allow-query" setting default, improperly permitting recursion to all clients. Affects BIND 9.9.12, 9.10.7, 9.11.3, 9.12.0->9.12.1-P2, the development release 9.13.0, and also releases 9.9.12-S1, 9.10.7-S1, 9.11.3-S1, and 9.11.3-S2 from BIND 9 Supported Preview Edition.Show less
4Debian
FedoraprojectOpensuse+1 more
5Debian Linux
Enterprise LinuxFedora+2 more
Jun 17, 2026
Jan 15, 2019
N/A· v4
5.2 MEDIUM· v3
2.7 LOW· v2
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that res...Show more
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.Show less
1Pivotal Software
1Concourse
Jun 17, 2026
Jan 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authen...Show more
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.Show less
5Canonical
DebianNetapp+2 more
21Active Iq Performance Analytics Services
Debian LinuxElement Software+18 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 a...Show more
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.Show less
1Apple
1Mac Os X
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.
1Apple
1Safari
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation.
1Apple
4Iphone Os
Mac Os XTvos+1 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state han...Show more
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.Show less
1Apple
1Mac Os X
Nov 21, 2024
Jan 11, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.
1Apple
3Apple Tv
Iphone OsMac Os
Nov 21, 2024
Jan 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by stor...Show more
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.Show less
1Apple
3Apple Tv
Iphone OsMac Os
Nov 21, 2024
Jan 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response val...Show more
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.Show less
1Cisco
1Identity Services Engine
Nov 21, 2024
Jan 10, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of save...Show more
A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin Portal. An attacker with read or write access to the Admin Portal could exploit this vulnerability by browsing to a page that contains sensitive data. An exploit could allow the attacker to recover passwords for unauthorized use and expose those accounts to further attack.Show less
1Cisco
1Unified Communications Manager
Nov 21, 2024
Jan 10, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorr...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in configuration pages. An attacker could exploit this vulnerability by logging in to the Cisco Unified Communications Manager web-based management interface and viewing the source code for the configuration page. A successful exploit could allow the attacker to recover passwords and expose those accounts to further attack.Show less
1Std42
1Elfinder
Jun 17, 2026
Jan 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
1Mate Desktop
1Mate Screensaver
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output de...Show more
mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output devices (such as additionally attached graphical outputs via HDMI, VGA, DVI, etc.) the content of a screensaver-locked session can be revealed. In some scenarios, the attacker can execute applications, such as by clicking with a mouse.Show less
1Nec
2Aterm Wf1200cr Firmware
Aterm Wg1200cr Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on the same network segment to obtain information registered on the device...Show more
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on the same network segment to obtain information registered on the device via unspecified vectors.Show less