← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
GoogleOpensuse+2 more
8Chrome
Debian LinuxEnterprise Linux Desktop+5 more
May 6, 2026
Jun 5, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modul...Show more
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.Show less
5Debian
GoogleOpensuse+2 more
8Chrome
Debian LinuxEnterprise Linux Desktop+5 more
May 6, 2026
Jun 5, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.
6Canonical
DebianGoogle+3 more
10Chrome
Debian LinuxEnterprise Linux Desktop+7 more
May 6, 2026
Jun 5, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and lever...Show more
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."Show less
1Siemens
1Siprotec Firmware
May 6, 2026
May 31, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant D...Show more
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain a limited amount of device memory content if network access was obtained. This vulnerability only affects EN100 Ethernet module included in SIPROTEC4 and SIPROTEC Compact devices.Show less
1Siemens
1Siprotec Firmware
May 6, 2026
May 31, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant D...Show more
A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.Show less
1Sixnet
2Bt 5 Series Cellular Router Firmware
Bt 6 Series Cellular Router Firmware
May 6, 2026
May 31, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sixnet BT-5xxx and BT-6xxx M2M devices before 3.8.21 and 3.9.x before 3.9.8 have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors.
1Moxa
5Miineport E1 4641 Firmware
Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 more
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices wit...Show more
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allow remote attackers to obtain sensitive cleartext information by reading a configuration file.Show less
1Blackbox
3Alertwerks Servsensor Contact Firmware
Alertwerks Servsensor FirmwareAlertwerks Servsensor Junior Firmware
May 6, 2026
May 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact wit...Show more
Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact with firmware before SP473 allow remote authenticated users to discover administrator and user passwords via unspecified vectors.Show less
1Hp
1Service Manager
May 6, 2026
May 30, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility com...Show more
HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components.Show less
1Hp
1Restful Interface Tool
May 6, 2026
May 30, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.
1Cisco
1Ucs Invicta C3124sa Appliance
May 6, 2026
May 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat crypt...Show more
Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by sniffing network traffic to an Autosupport server and leveraging knowledge of this key from another installation, aka Bug ID CSCur85504.Show less
1Cisco
1Webex Meeting Center
May 6, 2026
May 28, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or (2) hosting a meeting, aka Bug ID CSCux84312.
1Trend Micro
1Mobile Security
May 6, 2026
May 23, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive informa...Show more
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.Show less
4Canonical
LinuxNovell+1 more
6Linux
Linux KernelSuse Linux Enterprise Debuginfo+3 more
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from...Show more
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
May 6, 2026
May 23, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel...Show more
The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory via an X.25 Call Request.Show less
5Canonical
DebianLinux+2 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
May 6, 2026
May 23, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer inter...Show more
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 23, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via...Show more
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
May 23, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory b...Show more
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.Show less
3Canonical
LinuxNovell
5Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2 more
May 6, 2026
May 23, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a me...Show more
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.Show less
4Canonical
FedoraprojectLinux+1 more
11Fedora
Linux KernelSuse Linux Enterprise Debuginfo+8 more
May 6, 2026
May 23, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory vi...Show more
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.Show less