← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Db2
Apr 23, 2026
Apr 3, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive inf...Show more
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.Show less
2Osgeo
Umn
2Mapserver
Mapserver
Apr 23, 2026
Mar 31, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents withi...Show more
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.Show less
1Citrix
1Presentation Server Client
Apr 23, 2026
Mar 31, 2009
N/A· v4
N/A· v3
1.9 LOW· v2
Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.
1Lightneasy
1Lightneasy
Apr 23, 2026
Mar 30, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later...Show more
LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later accessed using $_REQUEST.Show less
1Cisco
1Cisco Ios
Apr 23, 2026
Mar 27, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading t...Show more
Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading to a Transmission Control Block (TCB) leak.Show less
1Devraj Mukherjee
1Openterracotta
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
index.php in Terracotta (aka OpenTerracotta) 0.6.1 allows remote attackers to obtain sensitive information via an invalid File parameter, which reveals the installation path in an error message.
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumer...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Mar 16, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary f...Show more
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.Show less
1Apple
1Itunes
Apr 23, 2026
Mar 14, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscr...Show more
Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.Show less
1Fujitsu
1Enhanced Support Facility
Apr 23, 2026
Mar 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via unspecified requests in a client connection.
1Stewart Howe
1Celerbb
Apr 23, 2026
Mar 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
1Socialsitegenerator
1Social Site Generator
Apr 23, 2026
Mar 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php.
1Typo3
1Typo3
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attack...Show more
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 23, 2026
Mar 5, 2009
N/A· v4
N/A· v3
7.1 HIGH· v2
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain re...Show more
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.Show less
1Activewebsoftwares
1Quick Tree View .net
Apr 23, 2026
Mar 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.
1Lobacher Patrick
1Simplefilebrowser
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the TYPO3 Simple File Browser (simplefilebrowser) extension 1.0.2 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors.
1Apache
1Tomcat
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
2.6 LOW· v2
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one reques...Show more
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.Show less
1Adobe
1Flash Player For Linux
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a director...Show more
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.Show less
1Rakhisoftware
1Rakhisoftware Shopping Cart
Apr 23, 2026
Feb 25, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.
1Vlad Alexa Mancini
1Phpfootball
Apr 23, 2026
Feb 23, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter...Show more
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.Show less