← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 29914434.
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate EFFECT_CMD_SET_PARAM and EFFECT_CMD...Show more
services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate EFFECT_CMD_SET_PARAM and EFFECT_CMD_SET_PARAM_DEFERRED commands, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 30204301.Show less
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not ensure that certain values are integers,...Show more
email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not ensure that certain values are integers, which allows attackers to read arbitrary attachments via a crafted application that provides a pathname value, aka internal bug 30745403.Show less
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android intern...Show more
drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29953313 and Qualcomm internal bug CR 1044072.Show less
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices allows attackers to obtain sensitive information via a crafted applicatio...Show more
sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29323142 and Qualcomm internal bug CR 1038127.Show less
1Linux
1Linux Kernel
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive informat...Show more
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.Show less
2Eclipse
Fedoraproject
2Fedora
Jetty
May 6, 2026
Oct 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
1Mypixs Project
1Mypixs
May 6, 2026
Oct 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
1Mp3 Jplayer Project
1Mp3 Jplayer
May 6, 2026
Oct 6, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
1Wptf Image Gallery Project
1Wptf Image Gallery
May 6, 2026
Oct 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote file download vulnerability in wptf-image-gallery v1.03
1Pivotal Software
1Cloud Foundry Cf Mysql
May 6, 2026
Oct 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information by reading syslog messages, as demonstrated by cleartext credentials.
1Cisco
1Secure Firewall Management Center
May 6, 2026
Oct 6, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
1Ibm
1Sterling Secure Proxy
May 6, 2026
Oct 6, 2016
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neith...Show more
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.Show less
1Cisco
1Nx Os
May 6, 2026
Oct 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CS...Show more
Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.Show less
1Fortinet
1Fortiwlc
May 6, 2026
Oct 5, 2016
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file.
1Cisco
1Firesight System Software
May 6, 2026
Oct 5, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.
1American Auto Matrix
2Aspect Matrix Building Automation Front End Solutions Application
Aspect Nexus Building Automation Front End Solutions Application
May 6, 2026
Oct 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read arbitrary files via...Show more
American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read arbitrary files via unspecified vectors, as demonstrated by the configuration file.Show less
2Ceph Project
Redhat
2Ceph
Ceph Storage
May 6, 2026
Oct 3, 2016
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
2Fedoraproject
Mongodb
2Fedora
Mongodb
May 6, 2026
Oct 3, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.