← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freedesktop
1Policykit
Apr 29, 2026
Apr 6, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.
1Apache
1Couchdb
Apr 29, 2026
Apr 5, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.
1Piotr Roszatycki
1Libnss Db
Apr 29, 2026
Apr 5, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack...Show more
The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module.Show less
1Google
1Chrome
Apr 29, 2026
Apr 1, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
1Microsoft
8Internet Explorer
Windows 2000Windows 2003 Server+5 more
Apr 29, 2026
Mar 31, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume...Show more
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."Show less
1Microsoft
7Internet Explorer
Windows 2000Windows 2003 Server+4 more
Apr 29, 2026
Mar 31, 2010
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted...Show more
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."Show less
1Apple
1Mac Os X Server
Apr 29, 2026
Mar 30, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demo...Show more
Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet.Show less
1Apple
1Webkit
Apr 29, 2026
Mar 26, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
1Mozilla
2Firefox
Seamonkey
Apr 29, 2026
Mar 26, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the...Show more
The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.Show less
1Chi Hoang
1Ch Lightem
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Power Extension Manager (ch_lightem) extension 1.0.34 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
1Apple
1Safari
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information fr...Show more
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.Show less
1Apple
1Safari
Apr 29, 2026
Mar 15, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information fr...Show more
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.Show less
1Ncpfs
1Ncpfs
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the...Show more
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name.Show less
1Cisco
1Digital Media Manager
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050.
3Apache
DebianFedoraproject
3Debian Linux
FedoraHttp Server
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a pare...Show more
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.Show less
1Moinmo
1Moinmoin
Apr 29, 2026
Feb 26, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information...Show more
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.Show less
1Becauseinter
1Bournal
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "ech...Show more
Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."Show less
1Iptechinside
1Com Jquarks
Apr 29, 2026
Feb 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path for Joomla! via unknown vectors.
1Google
1Chrome
Apr 29, 2026
Feb 18, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obta...Show more
The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obtain potentially sensitive information from process memory by providing insufficient data, related to use of a (1) thumbnail database or (2) HTML canvas.Show less
1Google
1Chrome
Apr 29, 2026
Feb 18, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive i...Show more
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.Show less