← Back
CWE-200

10,404 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,404)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zarafa
1Zarafa
May 6, 2026
Oct 20, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files.
1Zarafa
2Webapp
Zarafa
May 6, 2026
Oct 20, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because...Show more
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.Show less
1Status2k
1Status2k
May 6, 2026
Oct 20, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.
1Apple
1Mac Os X
May 6, 2026
Oct 18, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mobile-configuration profiles, which allows remote attackers to obtain sensitive information in opport...Show more
The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mobile-configuration profiles, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging access to an unintended proxy server.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by...Show more
Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading a message intended exclusively for other recipients.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces via an unspecified command to one interface.
1Jenkins
1Jenkins
May 6, 2026
Oct 17, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed l...Show more
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.Show less
1Sap
1Businessobjects Explorer
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and...Show more
polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and port in the cms parameter.Show less
1Sap
2Businessobjects
Businessobjects Xi
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers...Show more
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames via SecEnterprise authentication requests to the Session web service.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin...Show more
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
2Opensuse
Python
2Opensuse
Requests
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
4Canonical
DebianMageia+1 more
4Debian Linux
MageiaRequests+1 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
1Mozilla
1Firefox
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of renderi...Show more
Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element.Show less
1Linux
1Linux Kernel
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, whi...Show more
The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values.Show less
2Fedoraproject
Mozilla
2Bugzilla
Fedora
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveragin...Show more
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.Show less
1Bmc
1Track It!
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.
1Ibm
1Websphere Portal
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by...Show more
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.Show less
2Debian
Gnupg
2Debian Linux
Libgcrypt
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extrac...Show more
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the ability to collect voltage data from exposed metal, a different vector than CVE-2013-4576.Show less