← Back
CWE-200

10,332 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,332)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Coldfusion
Apr 29, 2026
Feb 1, 2011
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm fi...Show more
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosureShow less
1Ibm
1Websphere Portal
Apr 29, 2026
Jan 28, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
1Nvidia
1Cuda Toolkit
Apr 29, 2026
Jan 22, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read...Show more
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.Show less
1Polyvision
2Roomwizard
Roomwizard Firmware
Apr 29, 2026
Jan 12, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers...Show more
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the /admin/sign/DeviceSynch URI.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Jan 11, 2011
N/A· v4
N/A· v3
1.9 LOW· v2
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vect...Show more
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.Show less
1Mono
1Mono
Apr 29, 2026
Jan 11, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug."
1Mantisbt
1Mantisbt
Apr 29, 2026
Jan 3, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which reveals the installation path in an error message, related to an unsaf...Show more
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which reveals the installation path in an error message, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Apr 29, 2026
Jan 3, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory...Show more
The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.Show less
1Mybb
1Mybb
Apr 29, 2026
Dec 30, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Thr...Show more
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Threads block of the Portal Page.Show less
4Fedoraproject
LinuxOpensuse+1 more
7Fedora
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Dec 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instructi...Show more
The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.Show less
1Html Edit
1Html Edit Cms
Apr 29, 2026
Dec 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reve...Show more
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an error message.Show less
1Habariproject
1Habari
Apr 29, 2026
Dec 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admin/, which reveals the installation path in an error message.
2Dojofoundation
Ibm
2Dojo Toolkit
Rational Clearquest
Apr 29, 2026
Dec 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issu...Show more
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Dec 29, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containi...Show more
The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows local users to obtain potentially sensitive information about kernel memory use by listing this filename.Show less
3Linux
RedhatSuse
6Enterprise Linux Server
Enterprise Linux WorkstationLinux Kernel+3 more
Apr 29, 2026
Dec 23, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on t...Show more
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.Show less
1Hp
1Insight Management Agents
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path.
1Opera
1Opera Browser
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field o...Show more
Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visited web site.Show less
1Ibm
1Lotus Notes Traveler
Apr 29, 2026
Dec 16, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other...Show more
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.Show less
1Ibm
1Lotus Notes Traveler
Apr 29, 2026
Dec 16, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, r...Show more
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Dec 16, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cros...Show more
Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3342.Show less