CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,534 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 26 of 231
- CVE-2012-4420HIGHCVSS 7.5EG 7.52019-12-26
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonze…
- CVE-2012-4429MEDIUMCVSS v2 5.0EG 5.02012-10-01
Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
- CVE-2012-4503MEDIUMCVSS v2 5.0EG 5.02013-11-05
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or …
- CVE-2012-4511MEDIUMCVSS v2 5.8EG 5.82012-10-22
services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.
- CVE-2012-4530LOWCVSS v2 2.1EG 2.12013-02-18
The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
- CVE-2012-4583MEDIUMCVSS v2 4.0EG 4.02012-08-22
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within th…
- CVE-2012-4591MEDIUMCVSS v2 5.0EG 5.02012-08-22
About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, which allows remote attackers to obtain potentially sensitive information by visiting this p…
- CVE-2012-4605MEDIUMCVSS v2 5.0EG 5.02012-08-23
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScout Email Filter\SMTP" registry key, which makes it easier for remote attackers to obtain se…
- CVE-2012-4674MEDIUMCVSS v2 5.0EG 5.02012-08-26
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
- CVE-2012-4698MEDIUMCVSS v2 4.3EG 4.32012-12-23
Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-i…
- CVE-2012-4832LOWCVSS v2 1.9EG 1.92013-01-31
Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, w…
- CVE-2012-4837MEDIUMCVSS v2 4.0EG 4.02013-03-05
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.
- CVE-2012-4846MEDIUMCVSS v2 4.3EG 4.32012-12-19
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this…
- CVE-2012-4909MEDIUMCVSS v2 4.3EG 4.32012-09-13
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.
- CVE-2012-4976MEDIUMCVSS v2 5.0EG 5.02012-12-12
selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is not properly handled during construction of an error page.
- CVE-2012-5172MEDIUMCVSS v2 5.0EG 5.02012-11-16
The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application.
- CVE-2012-5180MEDIUMCVSS v2 4.3EG 4.32012-12-26
The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.
- CVE-2012-5182MEDIUMCVSS v2 4.3EG 4.32012-12-26
The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive information about logged locations via a crafted application.
- CVE-2012-5183LOWCVSS v2 2.6EG 2.62012-12-26
The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.
- CVE-2012-5222MEDIUMCVSS v2 5.0EG 5.02013-05-02
HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors.
- CVE-2012-5473MEDIUMCVSS v2 4.0EG 4.02012-11-21
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
- CVE-2012-5476MEDIUMCVSS 5.5EG 5.52019-12-30
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
- CVE-2012-5516LOWCVSS v2 2.1EG 2.12013-01-04
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive…
- CVE-2012-5535HIGHCVSS 7.5EG 7.52019-11-25
gnome-system-log polkit policy allows arbitrary files on the system to be read
- CVE-2012-5544MEDIUMCVSS v2 4.0EG 4.02012-12-03
The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.
- CVE-2012-5552MEDIUMCVSS v2 5.0EG 5.02012-12-03
The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks."
- CVE-2012-5554MEDIUMCVSS v2 5.0EG 5.02012-12-03
The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.
- CVE-2012-5561LOWCVSS v2 2.1EG 2.12013-03-01
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.
- CVE-2012-5570MEDIUMCVSS 4.3EG 4.32020-02-08
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
- CVE-2012-5589LOWCVSS v2 3.5EG 3.52012-12-26
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read ar…
- CVE-2012-5615MEDIUMCVSS v2 5.0EG 5.02012-12-03
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which all…
- CVE-2012-5624MEDIUMCVSS v2 4.3EG 4.32013-02-24
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QM…
- CVE-2012-5644MEDIUMCVSS 5.5EG 5.52019-11-25
libuser has information disclosure when moving user's home directory
- CVE-2012-5652MEDIUMCVSS v2 5.0EG 5.02013-01-03
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
- CVE-2012-5654MEDIUMCVSS v2 4.3EG 4.32013-01-03
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to …
- CVE-2012-5765MEDIUMCVSS v2 5.0EG 5.02012-12-20
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
- CVE-2012-5828MEDIUMCVSS 6.5EG 6.52020-02-10
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
- CVE-2012-5868LOWCVSS v2 2.6EG 2.62012-12-27
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a repla…
- CVE-2012-5884MEDIUMCVSS v2 5.0EG 5.02012-11-16
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability …
- CVE-2012-5915MEDIUMCVSS v2 5.0EG 5.02012-11-17
Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.l…
- CVE-2012-5916MEDIUMCVSS v2 5.0EG 5.02012-11-17
Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.s…
- CVE-2012-6049MEDIUMCVSS v2 5.0EG 5.02012-11-27
Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.
- CVE-2012-6052MEDIUMCVSS v2 5.0EG 5.02012-12-05
Wireshark 1.8.x before 1.8.4 allows remote attackers to obtain sensitive hostname information by reading pcap-ng files.
- CVE-2012-6077HIGHCVSS 7.5EG 7.52019-11-22
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
- CVE-2012-6078HIGHCVSS 7.5EG 7.52019-11-22
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
- CVE-2012-6079HIGHCVSS 7.5EG 7.52019-11-22
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
- CVE-2012-6091HIGHCVSS 7.5EG 7.52020-02-13
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
- CVE-2012-6097MEDIUMCVSS v2 4.3EG 4.32013-04-09
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
- CVE-2012-6104MEDIUMCVSS v2 5.0EG 5.02013-01-27
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
- CVE-2012-6105MEDIUMCVSS v2 5.0EG 5.02013-01-27
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by…
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →