CWE-200
10,332 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,332)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modifi...Show more |
libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a c...Show more |
Opera before 10.63 does not properly verify the origin of video content, which allows remote attackers to obtain sensitive information by using a video stream as HTML5 canvas content. |
SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentially sensitive information about open ports, via the apstoken parameter...Show more |
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a l...Show more |
OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public op...Show more |
Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process...Show more |
1Microsoft 1Internet Explorer Apr 29, 2026 Oct 13, 2010 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, a...Show more |
The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted informa...Show more |
Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1...Show more |
Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a...Show more |
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which al...Show more |
5Canonical DebianLinux+2 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Sep 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from...Show more |
5Canonical DebianLinux+2 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Sep 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive...Show more |
4Avaya CanonicalLinux+1 more10Aura Communication Manager Aura Presence ServicesAura Session Manager+7 moreApr 29, 2026 Sep 30, 2010 N/A· v4 8.1 HIGH· v3 6.4 MEDIUM· v2 The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk bl...Show more |
3Canonical LinuxSuse5Linux Enterprise Desktop Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 moreApr 29, 2026 Sep 30, 2010 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call. |
Unspecified vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to obtain sensitive information via unknown vectors. |
1Alcatel Lucent 2Ccagent Omnitouch Contact CenterApr 29, 2026 Sep 23, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the...Show more |
5Canonical LinuxOpensuse+2 more6Esx Linux KernelOpensuse+3 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information f...Show more |
Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors. |