CWE-200
10,373 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,373)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication pr...Show more |
The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive in...Show more |
HP Service Manager 9.30 through 9.32 allows remote authenticated users to obtain sensitive information via unspecified vectors. |
1Hp 2Imc Service Operation Management Software Module Intelligent Management CenterApr 29, 2026 Oct 13, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1647. |
The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' i...Show more |
1Hp 20Color Laserjet Cm4540 Color Laserjet Cm4540fColor Laserjet Cm4540fskm+17 moreApr 29, 2026 Oct 4, 2013 N/A· v4 N/A· v3 1.5 LOW· v2 HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read im...Show more |
2Emerson Enea4Dl 8000 Remote Terminal Unit OseRoc 800 Remote Terminal Unit+1 moreApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadc...Show more |
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process. |
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values use...Show more |
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to...Show more |
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors. |
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors. |
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching othe...Show more |
2Jgroups Redhat2Jboss Enterprise Application Platform JgroupApr 29, 2026 Sep 28, 2013 N/A· v4 N/A· v3 5.4 MEDIUM· v2 The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid crede...Show more |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3)...Show more |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remo...Show more |
1Ibm 4Data Studio Web Console Db2 Recovery ExpertInfosphere Optim Configuration Manager+1 moreApr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allow...Show more |
The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memor...Show more |
1Cisco 1Prime Data Center Network Manager Apr 29, 2026 Sep 23, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External...Show more |
1Cisco 1Prime Data Center Network Manager Apr 29, 2026 Sep 23, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCue77029. |