← Back
CWE-200

10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netapp
1Oncommand Unified Manager
Nov 21, 2024
Jun 22, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user...Show more
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.Show less
1Ibm
1Aix
Nov 21, 2024
Jun 22, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.
1Circontrol
1Circarlife Scada
Nov 21, 2024
Jun 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
1Redatam
1Redatam
Nov 21, 2024
Jun 21, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN parameter to the /redbin/rpwebutilities.exe/text URI.
6Canonical
CitrixDebian+3 more
14Core I3
Core I5Core I7+11 more
Nov 21, 2024
Jun 21, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side ch...Show more
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.Show less
1Reliablecontrols
1Mach Prowebcom Firmware
Jun 2, 2026
Jun 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml or job/job.json file, as demonstrated the Master Password field.
1Polycom
1Realpresence Web Suite
Nov 21, 2024
Jun 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chosen to turn off the video using a specific option). During those seconds...Show more
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chosen to turn off the video using a specific option). During those seconds, a meeting invitee may unknowingly be on camera with other participants able to view.Show less
1Liblnk Project
1Liblnk
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor ha...Show more
The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHubShow less
1Liblnk Project
1Liblnk
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk...Show more
The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHubShow less
1Libfsntfs Project
1Libfsntfs
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file....Show more
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHubShow less
1Libfsntfs Project
1Libfsntfs
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE...Show more
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHubShow less
1Libfsntfs Project
1Libfsntfs
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a cra...Show more
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHubShow less
1Libfsntfs Project
1Libfsntfs
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NO...Show more
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHubShow less
2Ovirt
Redhat
3Ovirt Engine
VirtualizationVirtualization Host
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
1Zuul Ci
1Zuul
Nov 21, 2024
Jun 19, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_ite...Show more
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items would be printed in the console. This could lead to accidentally leaking credentials or secrets.Show less
3Fedoraproject
PulpprojectRedhat
3Fedora
PulpSatellite
Nov 21, 2024
Jun 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view...Show more
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.Show less
1Perfsonar
1Monitoring And Debugging Dashboard
Nov 21, 2024
Jun 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.
1Perfsonar
1Monitoring And Debugging Dashboard
Nov 21, 2024
Jun 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.
1Perfsonar
1Monitoring And Debugging Dashboard
Nov 21, 2024
Jun 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.
1Perfsonar
1Monitoring And Debugging Dashboard
Nov 21, 2024
Jun 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.