← Back
CWE-200

10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing ubi image an uninitialized memory could be accessed.
1Brbackup Project
1Brbackup
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows local users to obtain sensitive information by listing the process.
1Kcapifony Project
1Kcapifony
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql command lines, which allows local users to obtain sensitive information by li...Show more
lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql command lines, which allows local users to obtain sensitive information by listing the processes.Show less
1Lawn Login Project
1Lawn Login
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
1Kajam Project
1Kajam
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password on the (1) mysqldump command line in the capture function and (2) mysql command line in the restore...Show more
vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password on the (1) mysqldump command line in the capture function and (2) mysql command line in the restore function, which allows local users to obtain sensitive information by listing the process.Show less
1Lean Ruport Project
1Lean Ruport
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
1Point Cli Project
1Point Cli
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
lib/commands/setup.rb in the point-cli gem 0.0.1 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
1Vladtheenterprising Project
1Vladtheenterprising
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.
2Backup Agoddard Project
Backup Checksum Project
2Backup Agoddard
Backup Checksum
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obta...Show more
(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process.Show less
1Cap Strap Project
1Cap Strap
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
lib/cap-strap/helpers.rb in the cap-strap gem 0.1.5 for Ruby places credentials on the useradd command line, which allows local users to obtain sensitive information by listing the process.
1Codders Dataset Project
1Codders Dataset
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to obtain sensitive infor...Show more
(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.Show less
1Freeipa
1Freeipa
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
4.0 MEDIUM· v2
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the passwor...Show more
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does not result in disclosure of password hashes belonging to active standard users. NOTE: some developers feel that this report is a suggestion for a design change to Stage User activation, not a statement of a vulnerability.Show less
1Apache
1Geode
Nov 21, 2024
Jan 10, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow r...Show more
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.Show less
1Apache
1Geode
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauth...Show more
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauthorized regions. In addition a user could invoke methods that allow remote code execution.Show less
1Apache
1Geode
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluste...Show more
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges.Show less
1Gm
1Shanghai Onstar
Nov 21, 2024
Jan 9, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitive information when th...Show more
A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitive information when the client connects to the server.Show less
1Apache
1Sling Jcr Contentloader
Nov 21, 2024
Jan 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information l...Show more
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoaderShow less
1Huawei
12S2300 Firmware
S2700 FirmwareS3300 Firmware+9 more
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
1Cobham
1Sea Tel 121 Firmware
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin.js URI. NOTE: default passwords for the...Show more
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin.js URI. NOTE: default passwords for the standard usernames are listed in the product's documentation: Dealer with password seatel3, SysAdmin with password seatel2, and User with password seatel1.Show less
1Vmware
2Horizon View
Workstation
Nov 21, 2024
Jan 5, 2018
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a...Show more
VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or may allow for a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this issue in conjunction with other bugs may allow a View desktop to leak information from host or may allow for a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.Show less