← Back
CWE-200

10,367 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,367)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
Apr 29, 2026
Jul 17, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.
1Moodle
1Moodle
Apr 29, 2026
Jul 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
1Yahoo
1Yahoo! Browser
Apr 29, 2026
Jul 16, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
1Moodle
1Moodle
Apr 29, 2026
Jul 16, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.
1Moodle
1Moodle
Apr 29, 2026
Jul 16, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.
1Moodle
1Moodle
Apr 29, 2026
Jul 16, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving us...Show more
Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.Show less
1Tiki
1Tikiwiki Cms/groupware
Apr 29, 2026
Jul 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
1Moodle
1Moodle
Apr 29, 2026
Jul 11, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
1Microsoft
5Windows 7
Windows Server 2003Windows Server 2008+2 more
Apr 29, 2026
Jul 10, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remot...Show more
The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."Show less
1Babygekko
1Baby Gekko
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) templates/html5demo/index.php.
1Joomla
1Joomla
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.
1Google
1Chrome
Apr 29, 2026
Jun 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access to an IFRAME element associated with a different domain.
1Bryce Hamrick
1Janrain Capture
Apr 29, 2026
Jun 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force...Show more
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.Show less
1Richardo Ante
1Ubercart Ajax Cart
Apr 29, 2026
Jun 27, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading...Show more
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.Show less
1Pro Face
2Pro Server Ex
Wingp Pc Runtime
Apr 29, 2026
Jun 25, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certai...Show more
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Jun 21, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecif...Show more
The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Jun 21, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stac...Show more
The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.Show less
1Canonical
1Ubuntu Linux
Apr 29, 2026
Jun 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read...Show more
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0949.Show less
1Openldap
1Openldap
Apr 29, 2026
Jun 17, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphe...Show more
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.Show less
1Dolphin Browser
2Dolphin Browser Hd
Dolphin For Pad
Apr 29, 2026
Jun 15, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Dolphin Browser HD application before 7.6 and Dolphin for Pad application before 1.0.1 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a craf...Show more
The Dolphin Browser HD application before 7.6 and Dolphin for Pad application before 1.0.1 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.Show less