CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,534 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 22 of 231
- CVE-2011-4742MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentia…
- CVE-2011-4748MEDIUMCVSS v2 5.0EG 5.02011-12-16
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain poten…
- CVE-2011-4751MEDIUMCVSS v2 5.0EG 5.02011-12-16
SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by readi…
- CVE-2011-4756MEDIUMCVSS v2 5.0EG 5.02011-12-16
Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as…
- CVE-2011-4759MEDIUMCVSS v2 5.0EG 5.02011-12-16
Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote …
- CVE-2011-4760MEDIUMCVSS v2 5.0EG 5.02011-12-16
Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive informatio…
- CVE-2011-4765MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive inf…
- CVE-2011-4766MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a direct request to wysiwyg/fckconfig.js. NOTE: CVE disputes this issue because ASP is only use…
- CVE-2011-4767MEDIUMCVSS v2 5.0EG 5.02011-12-16
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attacke…
- CVE-2011-4785HIGHCVSS v2 7.8EG 7.82012-01-10
Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with firmware before 07.080.3, LaserJet 4650 printer with firmware 07.006.0, and LaserJet 2430 printer with firmware 08.113.0_I35128 allows…
- CVE-2011-4817MEDIUMCVSS v2 4.0EG 4.02012-03-13
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service De…
- CVE-2011-4848MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by passwo…
- CVE-2011-4849MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an …
- CVE-2011-4850MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script ac…
- CVE-2011-4852MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier f…
- CVE-2011-4853MEDIUMCVSS v2 4.3EG 4.32011-12-16
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/us…
- CVE-2011-4866MEDIUMCVSS v2 6.4EG 6.42012-01-25
The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext password via a crafted application.
- CVE-2011-4872LOWCVSS v2 2.6EG 2.62012-02-05
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attacke…
- CVE-2011-4894MEDIUMCVSS v2 4.3EG 4.32011-12-23
Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.
- CVE-2011-4895MEDIUMCVSS v2 4.3EG 4.32011-12-23
Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.
- CVE-2011-4896MEDIUMCVSS v2 4.3EG 4.32011-12-23
Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances b…
- CVE-2011-4897MEDIUMCVSS v2 4.3EG 4.32011-12-23
Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.
- CVE-2011-4898MEDIUMCVSS v2 5.0EG 5.02012-01-30
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier f…
- CVE-2011-4900MEDIUMCVSS 6.5EG 6.52019-11-06
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
- CVE-2011-4901MEDIUMCVSS 6.5EG 6.52019-11-06
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.
- CVE-2011-4915MEDIUMCVSS 5.5EG 5.52020-02-20
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
- CVE-2011-4916MEDIUMCVSS 5.5EG 5.52022-07-12
Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.
- CVE-2011-4917MEDIUMCVSS 5.5EG 5.52022-04-18
In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.
- CVE-2011-4919HIGHCVSS 7.5EG 7.52019-11-19
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
- CVE-2011-4922LOWCVSS v2 2.1EG 2.12012-08-08
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.
- CVE-2011-4937HIGHCVSS 7.5EG 7.52020-02-04
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
- CVE-2011-4972HIGHCVSS 7.5EG 7.52019-11-13
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
- CVE-2011-5066LOWCVSS v2 2.1EG 2.12012-01-15
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Dat…
- CVE-2011-5067MEDIUMCVSS v2 4.0EG 4.02012-01-29
move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.
- CVE-2011-5126MEDIUMCVSS v2 5.0EG 5.02012-08-26
Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers to obtain sensitive authentication information by leveraging read access to a downloaded …
- CVE-2011-5282MEDIUMCVSS 5.3EG 5.32020-01-21
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
- CVE-2011-5314MEDIUMCVSS v2 5.0EG 5.02015-01-01
templates/default/index.php in Redaxscript 0.3.2 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
- CVE-2012-0010MEDIUMCVSS v2 4.3EG 4.32012-02-14
Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste In…
- CVE-2012-0037MEDIUMCVSS 6.5EG 6.52012-06-17
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML exter…
- CVE-2012-0046HIGHCVSS 7.5EG 7.52019-10-29
mediawiki allows deleted text to be exposed
- CVE-2012-0130MEDIUMCVSS v2 5.0EG 5.02012-04-05
HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors.
- CVE-2012-0236MEDIUMCVSS v2 5.0EG 5.02012-02-21
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
- CVE-2012-0263MEDIUMCVSS v2 4.0EG 4.02013-12-31
monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustype…
- CVE-2012-0316MEDIUMCVSS v2 5.0EG 5.02012-03-02
The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
- CVE-2012-0328MEDIUMCVSS v2 5.0EG 5.02012-03-19
Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.
- CVE-2012-0421LOWCVSS v2 2.1EG 2.12012-08-08
The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.
- CVE-2012-0425HIGHCVSS v2 7.8EG 7.82013-12-02
LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASS…
- CVE-2012-0433MEDIUMCVSS 3.3EG 5.52018-06-08
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.
- CVE-2012-0447MEDIUMCVSS v2 5.0EG 5.02012-02-01
Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by readin…
- CVE-2012-0456MEDIUMCVSS v2 5.0EG 5.02012-03-14
The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow …
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →