← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Edge
Windows 10Windows 8.1+1 more
May 6, 2026
Jun 16, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF...Show more
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.Show less
1Microsoft
1Outlook Web Access
May 6, 2026
Jun 16, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easi...Show more
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."Show less
1Huawei
1Honor Ws851 Firmware
May 6, 2026
Jun 14, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWPSIRT-2016-05053.
3Fedoraproject
OcamlOpensuse
3Fedora
OcamlOpensuse
May 6, 2026
Jun 13, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
3Canonical
MozillaOpensuse
4Firefox
LeapOpensuse+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
1Google
1Android
May 6, 2026
Jun 13, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application,...Show more
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 19285814.Show less
1Google
1Android
May 6, 2026
Jun 13, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not initialize certain data, which allows attackers to obtain sensitive...Show more
AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not initialize certain data, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 27855172.Show less
1Google
1Android
May 6, 2026
Jun 13, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a crafted application, aka internal bug 27777162.
1Huawei
1Mate 8 Firmware
May 6, 2026
Jun 10, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitiv...Show more
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors involving improper security status verification, aka HWPSIRT-2015-12007.Show less
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.
1Idera
1Uptime Infrastructure Monitor
May 6, 2026
Jun 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors.
1Canonical
2Lxd
Ubuntu Linux
May 6, 2026
Jun 9, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecifi...Show more
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.Show less
1Redhat
2Openshift
Openshift Origin
May 6, 2026
Jun 8, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
1Redhat
1Openshift
May 6, 2026
Jun 8, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.
1Redhat
1Openshift
May 6, 2026
Jun 8, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.
1Hp
1Universal Cmbd Foundation
May 6, 2026
Jun 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors.
1Hp
2Matrix Operating Environment
Systems Insight Manager
May 6, 2026
Jun 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026.
1Hp
2Matrix Operating Environment
Systems Insight Manager
May 6, 2026
Jun 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027.
2Criu
Opensuse
2Checkpoint/restore In Userspace
Opensuse
May 6, 2026
Jun 7, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
3Ibm
RedhatSuse
6Java Sdk
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Jun 6, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-...Show more
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.Show less