CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,526 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 15 of 231
- CVE-2010-3348MEDIUMCVSS v2 4.3EG 4.32010-12-16
Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Informatio…
- CVE-2010-3417MEDIUMCVSS v2 5.0EG 5.02010-09-16
Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors.
- CVE-2010-3664MEDIUMCVSS 6.5EG 6.52019-11-04
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
- CVE-2010-3673MEDIUMCVSS 5.3EG 5.32019-11-05
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
- CVE-2010-3764MEDIUMCVSS v2 5.0EG 5.02010-11-05
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
- CVE-2010-3796MEDIUMCVSS v2 4.3EG 4.32010-11-16
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.
- CVE-2010-3831MEDIUMCVSS v2 4.3EG 4.32010-11-26
Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a MobileMe Gallery server during a "Send t…
- CVE-2010-3845CRITICALCVSS 9.8EG 9.82017-08-08
libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
- CVE-2010-3851MEDIUMCVSS v2 4.7EG 4.72010-11-04
libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (…
- CVE-2010-3860MEDIUMCVSS v2 5.0EG 5.02010-12-08
IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user…
- CVE-2010-3861LOWCVSS v2 2.1EG 2.12010-12-10
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL etht…
- CVE-2010-3875LOWCVSS v2 2.1EG 2.12011-01-03
The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy …
- CVE-2010-3881LOWCVSS v2 2.1EG 2.12010-12-23
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
- CVE-2010-3886MEDIUMCVSS v2 4.3EG 4.32010-10-08
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attacke…
- CVE-2010-3902MEDIUMCVSS v2 5.0EG 5.02010-10-14
OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output posted to the public openconnect-devel mai…
- CVE-2010-3917MEDIUMCVSS 6.5EG 6.52020-02-06
Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.
- CVE-2010-3979MEDIUMCVSS v2 5.0EG 5.02010-10-18
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to …
- CVE-2010-3982MEDIUMCVSS v2 5.0EG 5.02010-10-18
SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentially sensitive information about open ports, via the apstoken parameter to the CrystalRepor…
- CVE-2010-4011MEDIUMCVSS v2 4.0EG 4.02010-11-17
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessin…
- CVE-2010-4046MEDIUMCVSS v2 4.3EG 4.32010-10-21
Opera before 10.63 does not properly verify the origin of video content, which allows remote attackers to obtain sensitive information by using a video stream as HTML5 canvas content.
- CVE-2010-4072LOWCVSS v2 1.9EG 1.92010-11-29
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related t…
- CVE-2010-4073LOWCVSS v2 1.9EG 1.92010-11-29
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl,…
- CVE-2010-4074LOWCVSS v2 1.9EG 1.92010-11-29
The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUN…
- CVE-2010-4075LOWCVSS v2 1.9EG 1.92010-11-29
The uart_get_count function in drivers/serial/serial_core.c in the Linux kernel before 2.6.37-rc1 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel sta…
- CVE-2010-4076LOWCVSS v2 1.9EG 1.92010-11-29
The rs_ioctl function in drivers/char/amiserial.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memo…
- CVE-2010-4077LOWCVSS v2 1.9EG 1.92010-11-29
The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel…
- CVE-2010-4079LOWCVSS v2 1.9EG 1.92010-11-29
The ivtvfb_ioctl function in drivers/media/video/ivtv/ivtvfb.c in the Linux kernel before 2.6.36-rc8 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel …
- CVE-2010-4080LOWCVSS v2 2.1EG 2.12010-11-30
The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via …
- CVE-2010-4112MEDIUMCVSS v2 5.0EG 5.02010-12-22
HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path.
- CVE-2010-4158LOWCVSS v2 2.1EG 2.12010-12-30
The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows lo…
- CVE-2010-4225MEDIUMCVSS v2 5.0EG 5.02011-01-11
Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug."
- CVE-2010-4349MEDIUMCVSS v2 5.0EG 5.02011-01-03
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which reveals the installation path in an error message, related to an unsafe call by MantisBT …
- CVE-2010-4354MEDIUMCVSS v2 5.0EG 5.02010-11-30
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I me…
- CVE-2010-4401MEDIUMCVSS v2 5.0EG 5.02010-12-06
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
- CVE-2010-4403MEDIUMCVSS v2 5.0EG 5.02010-12-06
The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.
- CVE-2010-4525LOWCVSS v2 1.9EG 1.92011-01-11
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.
- CVE-2010-4562MEDIUMCVSS v2 4.3EG 4.32012-02-02
Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Rep…
- CVE-2010-4563MEDIUMCVSS v2 5.0EG 5.02012-02-02
The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcpi…
- CVE-2010-4565LOWCVSS v2 2.1EG 2.12010-12-29
The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory …
- CVE-2010-4580MEDIUMCVSS v2 5.0EG 5.02010-12-22
Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visi…
- CVE-2010-4600MEDIUMCVSS v2 5.0EG 5.02010-12-29
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.
- CVE-2010-4608MEDIUMCVSS v2 5.0EG 5.02010-12-29
Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admin/, which reveals the installation path in an error message.
- CVE-2010-4611MEDIUMCVSS v2 5.0EG 5.02010-12-29
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installatio…
- CVE-2010-4625MEDIUMCVSS v2 5.0EG 5.02010-12-30
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Threads block of the P…
- CVE-2010-4760LOWCVSS v2 3.5EG 3.52011-03-18
Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by rea…
- CVE-2010-4781MEDIUMCVSS v2 5.0EG 5.02011-04-07
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error messa…
- CVE-2010-4804MEDIUMCVSS v2 4.3EG 4.32011-06-09
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
- CVE-2010-4822MEDIUMCVSS v2 4.3EG 4.32012-09-17
core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4, when the site is running in "live mode," allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.
- CVE-2010-5068MEDIUMCVSS v2 4.3EG 4.32011-12-07
The Cascading Style Sheets (CSS) implementation in Opera 10.5 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related …
- CVE-2010-5069MEDIUMCVSS v2 4.3EG 4.32011-12-07
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE…
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →