CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,534 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 25 of 231
- CVE-2012-3419MEDIUMCVSS v2 5.0EG 5.02012-08-27
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
- CVE-2012-3430LOWCVSS v2 2.1EG 2.12012-10-03
The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom o…
- CVE-2012-3474MEDIUMCVSS v2 5.0EG 5.02012-08-12
The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author o…
- CVE-2012-3493MEDIUMCVSS v2 5.8EG 5.82012-09-28
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd req…
- CVE-2012-3502MEDIUMCVSS v2 4.3EG 4.32012-08-22
The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a…
- CVE-2012-3519MEDIUMCVSS v2 5.0EG 5.02012-08-26
routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing side-cha…
- CVE-2012-3581LOWCVSS v2 3.3EG 3.32012-08-29
Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to obtain potentially sensitive information about component versions via unspecified vectors.
- CVE-2012-3650MEDIUMCVSS v2 4.3EG 4.32012-07-25
WebKit in Apple Safari before 6.0 accesses uninitialized memory locations during the rendering of SVG images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
- CVE-2012-3694MEDIUMCVSS v2 4.3EG 4.32012-07-25
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web site.
- CVE-2012-3714MEDIUMCVSS v2 4.3EG 4.32012-09-20
The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web si…
- CVE-2012-3718LOWCVSS v2 2.1EG 2.12012-09-20
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.
- CVE-2012-3724MEDIUMCVSS v2 5.0EG 5.02012-09-20
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a…
- CVE-2012-3725LOWCVSS v2 3.3EG 3.32012-09-20
The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive information about pre…
- CVE-2012-3733MEDIUMCVSS v2 4.3EG 4.32012-09-20
Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers to obtain potentiall…
- CVE-2012-3735LOWCVSS v2 2.1EG 2.12012-09-20
The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to Power Off" feature, which allows physically proximate attackers to see the most recently used third-party app by watching the device's scr…
- CVE-2012-3749MEDIUMCVSS v2 5.0EG 5.02012-11-03
The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted ap…
- CVE-2012-3796MEDIUMCVSS v2 5.0EG 5.02012-06-25
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.
- CVE-2012-3798MEDIUMCVSS v2 5.0EG 5.02012-06-27
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing …
- CVE-2012-3829MEDIUMCVSS v2 5.0EG 5.02012-07-03
Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.
- CVE-2012-3838MEDIUMCVSS v2 5.0EG 5.02012-07-03
Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) templates/html5demo/index.php.
- CVE-2012-3864MEDIUMCVSS v2 4.0EG 4.02012-08-06
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET …
- CVE-2012-3886MEDIUMCVSS v2 5.0EG 5.02012-07-26
AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attackers to obtain cleartext data by sniffing the local wireless network and then conducting a (1) brut…
- CVE-2012-3972MEDIUMCVSS v2 5.0EG 5.02012-08-29
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to ob…
- CVE-2012-3975MEDIUMCVSS v2 4.3EG 4.32012-08-29
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive informati…
- CVE-2012-3976MEDIUMCVSS v2 4.3EG 4.32012-08-29
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certifi…
- CVE-2012-3996MEDIUMCVSS v2 5.0EG 5.02012-07-12
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
- CVE-2012-4005MEDIUMCVSS v2 5.0EG 5.02012-08-07
The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obtain sensitive message information via a crafted application.
- CVE-2012-4006MEDIUMCVSS v2 4.3EG 4.32012-08-17
The GREE application before 1.4.0, GREE Tanken Dorirando application before 1.0.7, GREE Tsurisuta application before 1.5.0, GREE Monpura application before 1.1.1, GREE Kaizokuoukoku Columbus application before 1.3.5, GREE haconiwa applicat…
- CVE-2012-4007MEDIUMCVSS v2 4.3EG 4.32012-08-17
The mixi application before 4.3.0 for Android allows remote attackers to read potentially sensitive information in friends' comments via a crafted application that leverages the storage of these comments on an SD card.
- CVE-2012-4012MEDIUMCVSS v2 4.3EG 4.32012-09-08
The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file as…
- CVE-2012-4013MEDIUMCVSS v2 4.3EG 4.32012-09-14
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code i…
- CVE-2012-4046LOWCVSS v2 3.3EG 3.32012-12-24
The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"] value.
- CVE-2012-4116MEDIUMCVSS v2 4.3EG 4.32013-10-19
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server …
- CVE-2012-4168MEDIUMCVSS v2 4.3EG 4.32012-08-21
Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe A…
- CVE-2012-4197MEDIUMCVSS v2 5.0EG 5.02012-11-16
Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allows remote attackers to read attachment descriptions from priv…
- CVE-2012-4198MEDIUMCVSS v2 4.0EG 4.02012-11-16
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, …
- CVE-2012-4199MEDIUMCVSS v2 4.3EG 4.32012-11-16
template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates JavaScript function calls containing private product names …
- CVE-2012-4208MEDIUMCVSS v2 4.3EG 4.32012-11-21
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only res…
- CVE-2012-4219MEDIUMCVSS v2 5.0EG 5.02012-08-21
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc…
- CVE-2012-4235MEDIUMCVSS v2 5.0EG 5.02012-08-10
The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.
- CVE-2012-4254MEDIUMCVSS v2 4.3EG 4.32012-08-13
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
- CVE-2012-4255MEDIUMCVSS v2 4.3EG 4.32012-08-13
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
- CVE-2012-4256MEDIUMCVSS v2 5.0EG 5.02012-08-13
The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
- CVE-2012-4257MEDIUMCVSS v2 5.0EG 5.02012-08-13
Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.
- CVE-2012-4332MEDIUMCVSS v2 5.0EG 5.02012-08-14
The ShareYourCart plugin 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK.
- CVE-2012-4382MEDIUMCVSS 4.9EG 4.92017-10-19
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
- CVE-2012-4390MEDIUMCVSS v2 4.0EG 4.02012-09-05
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors.
- CVE-2012-4403MEDIUMCVSS v2 5.0EG 5.02012-09-19
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and th…
- CVE-2012-4407MEDIUMCVSS v2 5.0EG 5.02012-09-19
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry tha…
- CVE-2012-4411MEDIUMCVSS v2 4.6EG 4.62012-11-23
The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrators to obtain sensitive host resource information via the qemu monitor. NOTE: this might be a duplicate of CVE-2007-0998.
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →