CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modul...Show more |
5Debian GoogleOpensuse+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreMay 6, 2026 Jun 5, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions. |
6Canonical DebianGoogle+3 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreMay 6, 2026 Jun 5, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and lever...Show more |
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant D...Show more |
A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant D...Show more |
1Sixnet 2Bt 5 Series Cellular Router Firmware Bt 6 Series Cellular Router FirmwareMay 6, 2026 May 31, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Sixnet BT-5xxx and BT-6xxx M2M devices before 3.8.21 and 3.9.x before 3.9.8 have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors. |
1Moxa 5Miineport E1 4641 Firmware Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 moreMay 6, 2026 May 31, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices wit...Show more |
1Blackbox 3Alertwerks Servsensor Contact Firmware Alertwerks Servsensor FirmwareAlertwerks Servsensor Junior FirmwareMay 6, 2026 May 30, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact wit...Show more |
HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility com...Show more |
HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors. |
1Cisco 1Ucs Invicta C3124sa Appliance May 6, 2026 May 29, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat crypt...Show more |
Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or (2) hosting a meeting, aka Bug ID CSCux84312. |
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive informa...Show more |
4Canonical LinuxNovell+1 more6Linux Linux KernelSuse Linux Enterprise Debuginfo+3 moreMay 6, 2026 May 23, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 May 23, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel...Show more |
5Canonical DebianLinux+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 May 23, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer inter...Show more |
3Canonical LinuxNovell10Linux Kernel Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 moreMay 6, 2026 May 23, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via...Show more |
3Canonical LinuxNovell10Linux Kernel Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 moreMay 6, 2026 May 23, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory b...Show more |
3Canonical LinuxNovell5Linux Kernel Suse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2 moreMay 6, 2026 May 23, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a me...Show more |
4Canonical FedoraprojectLinux+1 more11Fedora Linux KernelSuse Linux Enterprise Debuginfo+8 moreMay 6, 2026 May 23, 2016 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory vi...Show more |