CWE-200
10,518 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,518)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Financial Transaction Manager Nov 21, 2024 Jun 13, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138378. |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Jun 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specif...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happ...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to mak...Show more |
4Canonical DebianMozilla+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 25, 2025 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow for information leakage of which applications are associated with specif...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this...Show more |
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that only allow WebExtensions to view specific content. This vulnerability a...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has...Show more |
4Canonical DebianMozilla+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 25, 2025 Jun 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This c...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could allow access to content that should be restricted in reader view. This vul...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue was discovered where the page could attempt to create these images throug...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the r...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie....Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open. This can allow style editor information used wit...Show more |
3Debian MozillaRedhat7Debian Linux Enterprise Linux AusEnterprise Linux Desktop+4 moreNov 21, 2024 Jun 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2. |
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website t...Show more |
3Debian MozillaRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 25, 2025 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data w...Show more |