← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Network Node Manager I
May 6, 2026
May 7, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.
3Canonical
ImagemagickRedhat
10Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 more
May 6, 2026
May 5, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
8Canonical
DebianGoogle+5 more
15Android
Debian LinuxEnterprise Linux Desktop+12 more
May 6, 2026
May 5, 2016
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a...Show more
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.Show less
1Emc
1Rsa Data Loss Prevention
May 6, 2026
May 3, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to obtain sensitive information by reading error messages.
3Canonical
LinuxOracle
3Linux Kernel
Ubuntu LinuxVm Server
May 6, 2026
May 2, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memo...Show more
The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.Show less
1Linux
1Linux Kernel
May 6, 2026
May 2, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.
1Mozilla
1Firefox
May 6, 2026
Apr 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and...Show more
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.Show less
1Lockon
1Ec Cube
May 6, 2026
Apr 30, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a different vulnerability than CVE-2016-1200.
1Cybozu
1Kintone
May 6, 2026
Apr 25, 2016
N/A· v4
2.5 LOW· v3
2.6 LOW· v2
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.
1Novell
1Service Desk
May 6, 2026
Apr 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensi...Show more
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.Show less
1Novell
1Service Desk
May 6, 2026
Apr 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFile...Show more
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.Show less
1Lexmark
1Printer Firmware
May 6, 2026
Apr 22, 2016
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate at...Show more
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.Show less
1Ecava
1Integraxor
May 6, 2026
Apr 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script a...Show more
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Ecava
1Integraxor
May 6, 2026
Apr 22, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
1Accuenergy
2Acuvim Ii Net Firmware
Acuvim Iir Net Firmware
May 6, 2026
Apr 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover a cleartext mail-server password via unspecified vectors.
3Canonical
DebianGnupg
3Debian Linux
LibgcryptUbuntu Linux
May 6, 2026
Apr 19, 2016
N/A· v4
2.0 LOW· v3
1.9 LOW· v2
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanation...Show more
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.Show less
1Apache
1Hadoop
May 6, 2026
Apr 19, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows...Show more
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.Show less
1Dotcms
1Dotcms
May 6, 2026
Apr 19, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive infor...Show more
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.Show less
4Debian
GoogleOpensuse+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive i...Show more
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted JPEG 2000 data in a PDF document.Show less