CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete. |
2Artifex Debian2Afpl Ghostscript Debian LinuxMay 13, 2026 Mar 7, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file. |
1Blackberry 1Good Control Server May 13, 2026 Mar 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain res...Show more |
1Dropbear Ssh Project 1Dropbear Ssh May 13, 2026 Mar 3, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident. |
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack. |
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack. |
The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via u...Show more |
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows re...Show more |
2Linux Redhat2Enterprise Linux Linux KernelMay 13, 2026 Mar 3, 2017 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances vi...Show more |
1Netapp 1Ontap Select Deploy Administration Utility May 13, 2026 Mar 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors. |
1Siemens 3Sinumerik Integrate Access Mymachine/ethernet Sinumerik Integrate Operate ClientSinumerik OperateMay 13, 2026 Mar 1, 2017 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read a...Show more |
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a...Show more |
5Allwinner AmdIntel+2 more20A64 Athlon Ii 640 X4Atom C2750+17 moreMay 13, 2026 Feb 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possib...Show more |
5Allwinner AmdIntel+2 more20A64 Athlon Ii 640 X4Atom C2750+17 moreMay 13, 2026 Feb 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possib...Show more |
5Allwinner AmdIntel+2 more20A64 Athlon Ii 640 X4Atom C2750+17 moreMay 13, 2026 Feb 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is poss...Show more |
Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors. |
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine. |
1Dlink 1Websmart Dgs 1510 Series Firmware May 13, 2026 Feb 23, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure...Show more |
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques. |
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table. |