← Back
CWE-200

10,369 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,369)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Internet Explorer
Apr 29, 2026
Jan 22, 2013
N/A· v4
N/A· v3
2.6 LOW· v2
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT elem...Show more
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.Show less
1Php
1Php
Apr 29, 2026
Jan 19, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zer...Show more
The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.Show less
5Canonical
MozillaOpensuse+2 more
14Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+11 more
Apr 29, 2026
Jan 13, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and...Show more
The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function of an XBL object.Show less
1Microsoft
1.net Framework
Apr 29, 2026
Jan 9, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive informat...Show more
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."Show less
1Redhat
1Enterprise Virtualization Manager
Apr 29, 2026
Jan 4, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users...Show more
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.Show less
1Nodewords Project
1Nodewords
Apr 29, 2026
Jan 3, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow r...Show more
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.Show less
1Drupal
1Drupal
Apr 29, 2026
Jan 3, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
1Wp Php Widget Project
1Wp Php Widget
Apr 29, 2026
Jan 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
1Opera
1Opera Browser
Apr 29, 2026
Jan 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.
1Opera
1Opera Browser
Apr 29, 2026
Jan 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern...Show more
Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern for a canvas.Show less
1Intel
1Connman
Apr 29, 2026
Jan 1, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remote attackers to obtain sensitive information via Bluetooth packets.
1Samsung
1Samsungdive
Apr 29, 2026
Dec 31, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort...Show more
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.Show less
1Wordpress
1Wordpress
Apr 29, 2026
Dec 27, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modi...Show more
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.Show less
1Openstack
2Folsom
Grizzly
Apr 29, 2026
Dec 26, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to ob...Show more
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).Show less
1Debian
2Advanced Package Tool
Apt
Apr 29, 2026
Dec 26, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/...Show more
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.Show less
1Netgenius
1Multilink
Apr 29, 2026
Dec 26, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing per...Show more
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.Show less
1Naver
1Loctouch
Apr 29, 2026
Dec 26, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.
1Naver
1Loctouch
Apr 29, 2026
Dec 26, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive information about logged locations via a crafted application.
1Opera
2Opera Mini
Opera Mobile
Apr 29, 2026
Dec 26, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.
1Dlink
2Dcs 932l
Dcs 932l Firmware
Apr 29, 2026
Dec 24, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"] value.