← Back
CWE-200

10,359 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,359)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Htc
9Desire Hd
Desire SDroid Incredible+6 more
Apr 29, 2026
Feb 5, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 a...Show more
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password f...Show more
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
1Linux
1Linux Kernel
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as de...Show more
The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping.Show less
1Microsoft
6Windows 2000
Windows 2003 ServerWindows 7+3 more
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining...Show more
Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 29, 2026
Feb 1, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive in...Show more
Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 29, 2026
Feb 1, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain...Show more
Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages.Show less
1Samba
1Samba
Apr 29, 2026
Jan 30, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
1Wordpress
1Wordpress
Apr 29, 2026
Jan 30, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, whic...Show more
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspectiveShow less
1Sitracker
1Support Incident Tracker
Apr 29, 2026
Jan 29, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.
1Sitracker
1Support Incident Tracker
Apr 29, 2026
Jan 29, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.
1Linux
1Linux Kernel
Apr 29, 2026
Jan 27, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.
1Rsa
1Envision
Apr 29, 2026
Jan 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors.
1Google
1Android
Apr 29, 2026
Jan 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.
1Kaixin001
1Kaixin001
Apr 29, 2026
Jan 25, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext password via a crafted ap...Show more
The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext password via a crafted application.Show less
1Ubermedia
1Twidroyd Legacy
Apr 29, 2026
Jan 25, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.
1Androidapptools
1Easy Filter
Apr 29, 2026
Jan 25, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted a...Show more
The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application.Show less
1Xiaomi
1Mitalk Messenger
Apr 29, 2026
Jan 25, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a crafted application.
1Flexerasoftware
1Installshield
Apr 29, 2026
Jan 19, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sen...Show more
Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe.Show less
1Apache
1Tomcat
Apr 29, 2026
Jan 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP...Show more
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.Show less