CWE-200
10,370 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,370)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Mar 15, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application. |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Mar 15, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application tha...Show more |
The l2tp_ip6_getname function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a...Show more |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Mar 15, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via...Show more |
The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via...Show more |
The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to obtain sensitive infor...Show more |
The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application. |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Mar 15, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap m...Show more |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Mar 15, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability. |
net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive information from kernel h...Show more |
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discoverin...Show more |
Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by i...Show more |
1Bitcoin 3Bitcoin Qt Bitcoin CoreBitcoindApr 29, 2026 Mar 12, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before 0.7.3rc1 make it easier for remote attackers to obtain potentially sensitive...Show more |
1Bitcoin 3Bitcoin Qt Bitcoin CoreBitcoindApr 29, 2026 Mar 12, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The penny-flooding protection mechanism in the CTxMemPool::accept method in bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before...Show more |
3Gnome OracleRedhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreApr 29, 2026 Mar 8, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email. |
The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, rel...Show more |
1Cisco 1Security Monitoring Analysis And Response System Apr 29, 2026 Mar 6, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The XML parser in Cisco Security Monitoring, Analysis, and Response System (MARS) allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an...Show more |
The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors. |
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unsp...Show more |
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file. |