← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28193342.
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28172322 and Qualcomm internal b...Show more
The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28172322 and Qualcomm internal bug CR1010222.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28174833 and MediaTek internal bug...Show more
The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28174833 and MediaTek internal bug ALPS02688832.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28175522 and MediaTek internal bug ALPS02...Show more
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28175522 and MediaTek internal bug ALPS02694389.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via...Show more
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
7.7 HIGH· v3
6.4 MEDIUM· v2
decoder/impeg2d_bitstream.c in mediaserver in Android 6.x before 2016-07-01 allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted application...Show more
decoder/impeg2d_bitstream.c in mediaserver in Android 6.x before 2016-07-01 allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted application, aka internal bug 28168413.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background appli...Show more
NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
3.3 LOW· v3
5.0 MEDIUM· v2
The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, a...Show more
The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mediaserver in Android 4.x before 4.4.4 allows remote attackers to obtain sensitive information via unspecified vectors, aka internal bug 27210135.
1Ibm
1I Access
May 6, 2026
Jul 8, 2016
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.
1Ibm
2Control Center
Sterling Control Center
May 6, 2026
Jul 8, 2016
N/A· v4
5.1 MEDIUM· v3
1.9 LOW· v2
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
1Ibm
1Websphere Application Server
May 6, 2026
Jul 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier fo...Show more
IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Ibm
1Websphere Application Server
May 6, 2026
Jul 7, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
2Opensuse
Phpmyadmin
2Opensuse
Phpmyadmin
May 6, 2026
Jul 5, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests o...Show more
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.Show less
1Siemens
1Sicam Pas/pqs
May 6, 2026
Jul 4, 2016
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database stoppage.
1Siemens
1Sicam Pas/pqs
May 6, 2026
Jul 4, 2016
N/A· v4
6.7 MEDIUM· v3
1.7 LOW· v2
Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.
1Emc
1Rsa Archer Egrc
May 6, 2026
Jul 4, 2016
N/A· v4
6.3 MEDIUM· v3
3.5 LOW· v2
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for...Show more
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.Show less
1Ibm
1Tivoli Storage Manager
May 6, 2026
Jul 3, 2016
N/A· v4
2.5 LOW· v3
2.1 LOW· v2
IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunist...Show more
IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 through 6.3 before 6.3.2.6, 6.4 before 6.4.3.3, and 7.1 before 7.1.6 allows local users to obtain sensitive retrieved data from arbitrary accounts in opportunistic circumstances by leveraging previous use of a symlink during archive and retrieve actions.Show less
1Cisco
1Epc3928 Firmware
May 6, 2026
Jul 3, 2016
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, ak...Show more
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, aka Bug ID CSCux17178.Show less
2Opensuse
Phpmyadmin
3Leap
OpensusePhpmyadmin
May 6, 2026
Jul 3, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier...Show more
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.Show less