CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,529 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 18 of 231
- CVE-2011-2890MEDIUMCVSS v2 5.0EG 5.02011-07-27
The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors involving the base variable, leading to disclosure o…
- CVE-2011-2891MEDIUMCVSS v2 5.0EG 5.02011-07-27
Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.
- CVE-2011-2898MEDIUMCVSS 5.5EG 5.52012-05-24
net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitiv…
- CVE-2011-2909MEDIUMCVSS v2 4.9EG 4.92014-02-15
The do_devinfo_ioctl function in drivers/staging/comedi/comedi_fops.c in the Linux kernel before 3.1 allows local users to obtain sensitive information from kernel memory via a copy of a short string.
- CVE-2011-2983MEDIUMCVSS v2 4.3EG 4.32011-08-18
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and…
- CVE-2011-2986MEDIUMCVSS v2 5.0EG 5.02011-08-18
Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive …
- CVE-2011-3011MEDIUMCVSS v2 5.0EG 5.02011-08-15
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.
- CVE-2011-3126MEDIUMCVSS v2 5.0EG 5.02011-08-10
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.
- CVE-2011-3128MEDIUMCVSS v2 5.0EG 5.02011-08-10
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.
- CVE-2011-3147HIGHCVSS 8.6EG 8.62019-04-22
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
- CVE-2011-3163LOWCVSS v2 1.2EG 1.22011-10-23
HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors.
- CVE-2011-3177HIGHCVSS 7.8EG 7.82017-09-08
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.
- CVE-2011-3179MEDIUMCVSS v2 5.0EG 5.02011-12-08
The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.
- CVE-2011-3201MEDIUMCVSS v2 4.3EG 4.32013-03-08
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
- CVE-2011-3220MEDIUMCVSS v2 4.3EG 4.32011-10-14
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
- CVE-2011-3242MEDIUMCVSS v2 5.0EG 5.02011-10-14
The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, which makes it easier for remote web servers to track users via a cookie.
- CVE-2011-3246MEDIUMCVSS v2 5.0EG 5.02011-10-14
CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (…
- CVE-2011-3253LOWCVSS v2 2.6EG 2.62011-10-14
CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate.
- CVE-2011-3264MEDIUMCVSS v2 5.0EG 5.02011-08-19
Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.
- CVE-2011-3265MEDIUMCVSS v2 5.0EG 5.02011-08-19
popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.
- CVE-2011-3269HIGHCVSS 7.5EG 7.52020-03-09
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
- CVE-2011-3309MEDIUMCVSS v2 4.3EG 4.32012-05-02
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IK…
- CVE-2011-3388MEDIUMCVSS v2 4.3EG 4.32011-09-06
Opera before 11.51 allows remote attackers to cause an insecure site to appear secure or trusted via unspecified actions related to Extended Validation and loading content from trusted sources in an unspecified sequence that causes the add…
- CVE-2011-3404MEDIUMCVSS v2 4.3EG 4.32011-12-14
Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a c…
- CVE-2011-3427LOWCVSS v2 2.6EG 2.62011-10-14
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain …
- CVE-2011-3431LOWCVSS v2 2.1EG 2.12011-10-14
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen.
- CVE-2011-3441MEDIUMCVSS v2 4.3EG 4.32011-11-11
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.
- CVE-2011-3447MEDIUMCVSS v2 4.3EG 4.32012-02-02
CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.
- CVE-2011-3452MEDIUMCVSS v2 4.3EG 4.32012-02-02
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.
- CVE-2011-3497HIGHCVSS v2 10.0EG 10.02011-09-16
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
- CVE-2011-3502MEDIUMCVSS v2 5.0EG 5.02011-09-16
The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot).
- CVE-2011-3580MEDIUMCVSS v2 5.0EG 5.02011-09-30
IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.
- CVE-2011-3613HIGHCVSS 7.5EG 7.52020-01-22
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
- CVE-2011-3634LOWCVSS v2 2.6EG 2.62014-03-01
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
- CVE-2011-3649LOWCVSS v2 2.6EG 2.62011-11-09
Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a di…
- CVE-2011-3653MEDIUMCVSS v2 5.0EG 5.02011-11-09
Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read …
- CVE-2011-3663MEDIUMCVSS v2 4.3EG 4.32011-12-21
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within tha…
- CVE-2011-3670MEDIUMCVSS v2 5.0EG 5.02012-02-01
Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive informati…
- CVE-2011-3694MEDIUMCVSS v2 5.0EG 5.02011-09-27
The Server Administration Console in NetSaro Enterprise Messenger Server 2.0 allows remote attackers to read application source code by appending a %00 character to a URL.
- CVE-2011-3695MEDIUMCVSS v2 5.0EG 5.02011-09-23
111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files.
- CVE-2011-3696MEDIUMCVSS v2 5.0EG 5.02011-09-23
60cycleCMS 2.5.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by post.php and certain other files.
- CVE-2011-3697MEDIUMCVSS v2 5.0EG 5.02011-09-23
Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/graph/jpgraph/jpgraph_radar.php and certain othe…
- CVE-2011-3698MEDIUMCVSS v2 5.0EG 5.02011-09-23
AdaptCMS 2.0.2 Beta allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by inc/poll_vote.php and certain other files.
- CVE-2011-3699MEDIUMCVSS v2 5.0EG 5.02011-09-23
John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and c…
- CVE-2011-3700MEDIUMCVSS v2 5.0EG 5.02011-09-23
Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang…
- CVE-2011-3701MEDIUMCVSS v2 5.0EG 5.02011-09-23
AlegroCart 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by common.php and certain other files.
- CVE-2011-3702MEDIUMCVSS v2 5.0EG 5.02011-09-23
Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/template.php and certain other files.
- CVE-2011-3703MEDIUMCVSS v2 5.0EG 5.02011-09-23
AneCMS 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by widgets/menu/index.php and certain other files.
- CVE-2011-3704MEDIUMCVSS v2 5.0EG 5.02011-09-23
appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php.
- CVE-2011-3705MEDIUMCVSS v2 5.0EG 5.02011-09-23
Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files.
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →