CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 7Office Office Compatibility PackOffice Web Apps+4 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to ob...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Mar 17, 2017 N/A· v4 2.6 LOW· v3 2.3 LOW· v2 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtai...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Informati...Show more |
1Microsoft 14Live Meeting LyncOffice+11 moreMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all...Show more |
Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different fro...Show more |
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Mar 17, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Mar 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with an...Show more |
1Microsoft 14Live Meeting LyncOffice+11 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensiti...Show more |
1Microsoft 1Internet Explorer May 13, 2026 Mar 17, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This...Show more |
1Microsoft 4Windows 10 Windows Server 2008Windows Server 2012+1 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a cra...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Mar 17, 2017 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote...Show more |