CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Adobe Hp2Business Service Management Livecycle Data ServicesMay 6, 2026 Aug 25, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other product...Show more |
Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu. |
2Linux Pam Oracle2Linux Pam Sparc Opl Service ProcessorMay 6, 2026 Aug 24, 2015 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via...Show more |
1Ibm 2Integration Bus Websphere Message BrokerMay 6, 2026 Aug 23, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obta...Show more |
1Ibm 3Tivoli Storage Fastback For Microsoft Exchange Tivoli Storage Flashcopy Manager For Microsoft Exchange ServerTivoli Storage Manager For Mail Data Protection For Microsoft Exchange ServerMay 6, 2026 Aug 23, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCo...Show more |
1Ibm 3Tivoli Storage Flashcopy Manager Tivoli Storage Manager For Databases Data Protection For Microsoft Sql ServerTivoli Storage Manager For Mail Data Protection For Microsoft Exchange ServerMay 6, 2026 Aug 23, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Mi...Show more |
1Ibm 3Tivoli Storage Flashcopy Manager Tivoli Storage Manager For Databases Data Protection For Microsoft Sql ServerTivoli Storage Manager For Mail Data Protection For Microsoft Exchange ServerMay 6, 2026 Aug 23, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, and Tivoli Storage Fla...Show more |
1Ibm 2Websphere Application Server Websphere Virtual EnterpriseMay 6, 2026 Aug 22, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information abo...Show more |
Lockbox in EMC Documentum D2 before 4.5 uses a hardcoded passphrase when a server lacks a D2.Lockbox file, which makes it easier for remote authenticated users to decrypt admin tickets by locating this passphrase in a de...Show more |
EMC Documentum Content Server before 7.0 P20, 7.1 before P18, and 7.2 before P02, when RPC tracing is configured, stores certain obfuscated password data in a log file, which allows remote authenticated users to obtain s...Show more |
1Cisco 1Telepresence Video Communication Server Software May 6, 2026 Aug 20, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID CSCuv12340...Show more |
1Cisco 1Telepresence Video Communication Server Software May 6, 2026 Aug 20, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive password-hash information by reading the snapshot file, aka Bug I...Show more |
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image. |
1Cisco 1Edge Bluebird Operating System May 6, 2026 Aug 19, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968. |
1Apache Solr Real Time Project 1Apache Solr Real Time May 6, 2026 Aug 18, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search. |
1Dynamic Display Block Project 1Dynamic Display Block May 6, 2026 Aug 18, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission. |
The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intende...Show more |
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF i...Show more |
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted PNG im...Show more |
AppleGraphicsControl in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app. |