← Back
CWE-200

10,405 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Cordova
May 6, 2026
Nov 15, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.
6Apple
CanonicalDebian+3 more
6Debian Linux
HyperionLibcurl+3 more
May 6, 2026
Nov 15, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that...Show more
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.Show less
1Freebsd
1Freebsd
May 6, 2026
Nov 13, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which...Show more
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.Show less
1Open Atrium Project
1Open Atrium
May 6, 2026
Nov 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node.
1Bad Behavior Project
1Bad Behavior
May 6, 2026
Nov 12, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords, which allows remote authenticated users with the "administer bad behavior" permission to obtain sen...Show more
The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords, which allows remote authenticated users with the "administer bad behavior" permission to obtain sensitive information by reading a log file.Show less
1Adobe
4Air
Air SdkAir Sdk & Compiler+1 more
May 6, 2026
Nov 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler be...Show more
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow remote attackers to discover session tokens via unspecified vectors.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Nov 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 8 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Nov 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 9 and 10 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Nov 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Nov 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."
1Linux
1Linux Kernel
May 6, 2026
Nov 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading...Show more
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.Show less
1Ibm
1Sterling B2b Integrator
May 6, 2026
Nov 8, 2014
N/A· v4
N/A· v3
1.9 LOW· v2
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by read...Show more
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.Show less
1Eucalyptus
1Eucalyptus
May 6, 2026
Nov 7, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.
1Eucalyptus
1Eucalyptus
May 6, 2026
Nov 7, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Eucalyptus 4.0.0 through 4.0.1, when the log level is set to INFO, logs user and system passwords, which allows local users to obtain sensitive information by reading cloud-requests.log.
1Cisco
1Unity Connection
May 6, 2026
Nov 7, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Unified Messaging Service (UMS) in Cisco Unity Connection 10.5 and earlier allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCur06493.
1Sap
1Business Intelligence Development Workbench
May 6, 2026
Nov 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain audit event details via unspecified vectors.
1Sap
1Business Intelligence Development Workbench
May 6, 2026
Nov 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.
1Accuenergy
2Acuvim Ii
Axm Net
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.
1Ibm
1Notes Traveler
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the networ...Show more
The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.Show less
1Eset
1Personal Firewall Ndis Filter
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensiti...Show more
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.Show less