← Back
CWE-200

10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 170...Show more
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0829 and CVE-2018-0832.Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 170...Show more
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0830 and CVE-2018-0832.Show less
1Microsoft
1Edge
Nov 21, 2024
Feb 15, 2018
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-201...Show more
Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0839.Show less
1Microsoft
2Windows 7
Windows Server 2008
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows E...Show more
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0760, and CVE-2018-0855.Show less
1Microsoft
3Windows 7
Windows Server 2008Windows Server 2012
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Windows Server 2012 allows information disclosure, due to how the Windows EOT font engine handles embedded...Show more
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Windows Server 2012 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0761, and CVE-2018-0855.Show less
1Microsoft
2Windows 7
Windows Server 2008
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows E...Show more
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0760, CVE-2018-0761, and CVE-2018-0855.Show less
1Apache
1Activemq
Nov 21, 2024
Feb 13, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
1Hyland
1Saperion Web Client
Jun 17, 2026
Feb 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-62672248.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Android media framework (libstagefright_soft_avcenc). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-69065651.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Android framework (crypto framework). Product: Android. Versions: 8.0, 8.1. ID: A-68694819.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Android framework (ui framework). Product: Android. Versions: 8.0. ID: A-66244132.
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
4.2 MEDIUM· v3
4.7 MEDIUM· v2
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privil...Show more
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.Show less
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges neede...Show more
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68953950.Show less
2Dedecms
Phome
2Dedecms
Empirecms
Jun 17, 2026
Feb 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
1Postgresql
1Postgresql
Nov 21, 2024
Feb 9, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned tabl...Show more
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.Show less
1Ibm
1Sametime
Nov 21, 2024
Feb 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.
1Zblogcn
1Z Blogphp
Jun 17, 2026
Feb 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.