← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linux
1Linux Kernel
May 6, 2026
Feb 8, 2016
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR prote...Show more
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.Show less
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an u...Show more
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25800375.Show less
1Sauter
1Moduweb Vision
May 6, 2026
Feb 6, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
1Ge
1Snmp/web Adapter Firmware
May 6, 2026
Feb 5, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.
1Apple
1Iphone Os
May 6, 2026
Feb 1, 2016
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.
1Apple
2Iphone Os
Safari
May 6, 2026
Feb 1, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain...Show more
The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history information via a crafted web site.Show less
2Mozilla
Opensuse
3Firefox
LeapOpensuse
May 6, 2026
Jan 31, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists bec...Show more
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.Show less
1Carel
1Plantvisor Enhanced
May 6, 2026
Jan 30, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.
2Matroska
Opensuse
3Leap
LibmatroskaOpensuse
May 6, 2026
Jan 29, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process heap memory via crafted EBML lacing, which triggers an invalid memory ac...Show more
The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process heap memory via crafted EBML lacing, which triggers an invalid memory access.Show less
1Matroska
1Libebml
May 6, 2026
Jan 29, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an...Show more
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.Show less
1Matroska
1Libebml
May 6, 2026
Jan 29, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid mem...Show more
The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access.Show less
2Golang
Opensuse
2Go
Leap
May 6, 2026
Jan 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vect...Show more
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.Show less
1Ibm
1Spectrum Scale
May 6, 2026
Jan 27, 2016
N/A· v4
5.9 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover an LDAP password via unspecified vectors.
1Ibm
13Change And Configuration Management Database
Maximo Asset ManagementMaximo Asset Management Essentials+10 more
May 6, 2026
Jan 27, 2016
N/A· v4
4.1 MEDIUM· v3
4.9 MEDIUM· v2
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartClo...Show more
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow local users to obtain sensitive information by leveraging administrative privileges and reading log files.Show less
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
4.1 MEDIUM· v3
2.7 LOW· v2
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows allows remote attackers to obtain sensitive file names via a crafted file request to /list.
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
8.0 HIGH· v3
4.3 MEDIUM· v2
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-i...Show more
Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.Show less
1Google
1Chrome
May 6, 2026
Jan 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protect...Show more
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.Show less
1Google
1Chrome
May 6, 2026
Jan 25, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies...Show more
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.Show less
1Google
1Chrome
May 6, 2026
Jan 25, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows re...Show more
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.Show less
1Php
1Php
May 6, 2026
Jan 19, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of servi...Show more
The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.Show less