← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Veritas File System
Apr 23, 2026
Oct 21, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem blocks during creation of a file, which allow...Show more
qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem blocks during creation of a file, which allows local users to obtain sensitive information by creating and then reading files.Show less
1Hisanaga Electric Co
1Hisa Cart
Apr 23, 2026
Oct 21, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors.
1Apple
1Iphone
Apr 23, 2026
Oct 17, 2008
N/A· v4
N/A· v3
1.2 LOW· v2
Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by performing an Emergency Call tap and then...Show more
Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by performing an Emergency Call tap and then reading SMS messages on the device screen, aka Apple bug number 6267416.Show less
1Hp
1Systems Insight Manager
Apr 23, 2026
Oct 17, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive information via unspecified vectors.
1Microsoft
1Internet Explorer
Apr 23, 2026
Oct 15, 2008
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive...Show more
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."Show less
1Apple
1Mail
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server owners and remote man-in-the-middle attacker...Show more
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server owners and remote man-in-the-middle attackers to read sensitive mail.Show less
1V Webmail
1V Webmail
Apr 23, 2026
Oct 8, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error...Show more
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Oct 6, 2008
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that...Show more
The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within the bounds established by SCTP_AUTH_HMAC_ID_MAX, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function, a different vulnerability than CVE-2008-4113.Show less
1Vmware
1Virtualcenter
Apr 23, 2026
Oct 6, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the...Show more
VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.Show less
2Debian
Lighttpd
2Debian Linux
Lighttpd
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attacke...Show more
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.Show less
2Debian
Lighttpd
2Debian Linux
Lighttpd
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restriction...Show more
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.Show less
1Opera
1Opera Browser
Apr 23, 2026
Sep 27, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of J...Show more
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of JavaScript events and appropriate manipulation."Show less
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted...Show more
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.Show less
1Attachmax
1Dolphin
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: som...Show more
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: some of these details are obtained from third party information.Show less
1Integramod
1Integramod
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.
1Nooms
1Nooms
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "...Show more
Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."Show less
1Memht
1Memht Portal
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
2.6 LOW· v2
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
1Oscommerce
1Oscommerce
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
1Phpbb
1Phpbb
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack aga...Show more
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.Show less
1Talkback
1Talkback
Apr 23, 2026
Sep 16, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.