CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintena...Show more |
1Oracle 2Enterprise Manager Database Control Enterprise Manager Grid ControlMay 6, 2026 Jul 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to a...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Microsoft 5Windows 8 Windows 8.1Windows Rt+2 moreMay 6, 2026 Jul 14, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted...Show more |
1Microsoft 6Windows 7 Windows 8Windows 8.1+3 moreMay 6, 2026 Jul 14, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted...Show more |
1Microsoft 9Windows 2003 Server Windows 7Windows 8+6 moreMay 6, 2026 Jul 14, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wi...Show more |
Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass." |
Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability." |
Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability." |
Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability." |
Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability." |
1Microsoft 3Excel Excel ViewerSharepoint ServerMay 6, 2026 Jul 14, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR...Show more |
1Microsoft 3Windows 2003 Server Windows Server 2008Windows Server 2012May 6, 2026 Jul 14, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remo...Show more |
Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." |