CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Cloud Orchestrator Smartcloud OrchestratorMay 13, 2026 Feb 8, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects...Show more |
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the curr...Show more |
1Ibm 1Infosphere Information Server May 13, 2026 Feb 8, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information. |
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sen...Show more |
1Ibm 2Rational Doors Next Generation Rational Requirements ComposerMay 13, 2026 Feb 8, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system. |
1Ibm 1Rational Collaborative Lifecycle Management May 13, 2026 Feb 8, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user. |
1Citrix 1Netscaler Application Delivery Controller Firmware May 13, 2026 Feb 8, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obta...Show more |
The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption. |
1A10networks 1Advanced Core Operating System May 13, 2026 Feb 8, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused non...Show more |
Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue...Show more |
1Ibm 3Client Application Access DominoNotesMay 13, 2026 Feb 8, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and...Show more |
2Google Linux2Android Linux KernelMay 13, 2026 Feb 8, 2017 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires c...Show more |
2Google Linux2Android Linux KernelMay 13, 2026 Feb 8, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to acces...Show more |
An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sen...Show more |
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensit...Show more |
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a gener...Show more |
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated a...Show more |
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High be...Show more |
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Hi...Show more |
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Hi...Show more |