← Back
CWE-200

10,367 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,367)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
MozillaOpensuse+2 more
12Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+9 more
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoo...Show more
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain...Show more
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.Show less
6Canonical
DebianMozilla+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows rem...Show more
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.Show less
1Symantec
1Messaging Gateway
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to obtain potentially sensitive information about component versions via unspecified vectors.
1Wimleers
1Cdn
Apr 29, 2026
Aug 28, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrate...Show more
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.Show less
1Sgi
1Performance Co Pilot
Apr 29, 2026
Aug 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
1Debian
1Cifs Utils
Apr 29, 2026
Aug 27, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
1Bluecoat
1Sgos
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers to obtain sensitive authentication information by leveraging read acce...Show more
Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers to obtain sensitive authentication information by leveraging read access to a downloaded core file.Show less
1Pluxml
1Pluxml
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
1Silverstripe
1Silverstripe
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
1Silverstripe
1Silverstripe
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1, when running on servers with certain configurations, allows remote attackers to obtain sensitive information via a direct request to PHP files in the (1) sapphire,...Show more
SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1, when running on servers with certain configurations, allows remote attackers to obtain sensitive information via a direct request to PHP files in the (1) sapphire, (2) cms, or (3) mysite folders, which reveals the installation path in an error message.Show less
1Tor
1Tor
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection vi...Show more
routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing side-channel attack.Show less
1Websense
1Websense Email Security
Apr 29, 2026
Aug 23, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScout Email Filter\SMTP" registry key, which makes it easier for remote att...Show more
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScout Email Filter\SMTP" registry key, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.Show less
1Websense
1Websense Email Security
Apr 29, 2026
Aug 23, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive information from the JBoss status page via an unspecified query.
1Apache
1Http Server
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations tha...Show more
The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.Show less
1Mcafee
1Enterprise Mobility Manager
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, which allows remote attackers to obtain potentially sensitive information...Show more
About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, which allows remote attackers to obtain potentially sensitive information by visiting this page.Show less
1Mcafee
2Email And Web Security
Email Gateway
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by n...Show more
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.Show less
1Mcafee
1Host Data Loss Prevention
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
The Web Post Protection feature in McAfee Host Data Loss Prevention (DLP) 3.x before 3.0.100.10 and 9.x before 9.0.0.422, when HTTP Capture mode is enabled, allows local users to obtain sensitive information from web tra...Show more
The Web Post Protection feature in McAfee Host Data Loss Prevention (DLP) 3.x before 3.0.100.10 and 9.x before 9.0.0.422, when HTTP Capture mode is enabled, allows local users to obtain sensitive information from web traffic by reading unspecified files.Show less
1Adobe
3Air
Air SdkFlash Player
Apr 29, 2026
Aug 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on A...Show more
Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow remote attackers to read content from a different domain via a crafted web site.Show less
1Phpmyadmin
1Phpmyadmin
Apr 29, 2026
Aug 21, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusio...Show more
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.Show less