CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,534 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 29 of 231
- CVE-2013-2061LOWCVSS v2 2.6EG 2.62013-11-18
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constan…
- CVE-2013-2074MEDIUMCVSS v2 5.0EG 5.02014-02-05
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
- CVE-2013-2076MEDIUMCVSS v2 4.3EG 4.32013-08-28
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating poi…
- CVE-2013-2086MEDIUMCVSS v2 5.0EG 5.02014-03-14
The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.
- CVE-2013-2164LOWCVSS v2 2.1EG 2.12013-07-04
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
- CVE-2013-2202MEDIUMCVSS v2 4.3EG 4.32013-07-08
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVE-2013-2243MEDIUMCVSS v2 4.0EG 4.02013-07-29
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a docume…
- CVE-2013-2261HIGHCVSS 7.5EG 7.52019-11-04
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
- CVE-2013-2262HIGHCVSS 7.5EG 7.52019-11-04
Cryptocat strophe.js before 2.0.22 has information disclosure
- CVE-2013-2264MEDIUMCVSS v2 5.0EG 5.02013-04-01
The SIP channel driver in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1.8.15-cert2; Asterisk Business Edition (BE) C.3.x before C.3.8.1; and Asterisk Digiumphone…
- CVE-2013-2272MEDIUMCVSS v2 5.0EG 5.02013-03-12
The penny-flooding protection mechanism in the CTxMemPool::accept method in bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before 0.7.3rc1 allows rem…
- CVE-2013-2273MEDIUMCVSS v2 5.0EG 5.02013-03-12
bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before 0.7.3rc1 make it easier for remote attackers to obtain potentially sensitive information about …
- CVE-2013-2302LOWCVSS v2 1.9EG 1.92013-04-04
TransWARE Active! mail 6, when an external public interface is used, allows local users to obtain sensitive information belonging to arbitrary users by leveraging shell access, as demonstrated by a TELNET or SSH session to the server.
- CVE-2013-2308MEDIUMCVSS v2 4.0EG 4.02013-05-09
The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors.
- CVE-2013-2322LOWCVSS v2 3.5EG 3.52013-06-28
HP SQL/MX 3.2 and earlier on NonStop servers, when SQL/MP Objects are used, allows remote authenticated users to obtain sensitive information via unspecified vectors, aka the "SQL/MP index" issue.
- CVE-2013-2371MEDIUMCVSS v2 5.0EG 5.02013-03-15
The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.
- CVE-2013-2499HIGHCVSS 7.5EG 7.52020-01-27
SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.
- CVE-2013-2600HIGHCVSS 7.5EG 7.52019-11-01
MiniUPnPd has information disclosure use of snprintf()
- CVE-2013-2624MEDIUMCVSS 5.3EG 5.32020-02-03
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.
- CVE-2013-2631MEDIUMCVSS 5.3EG 5.32020-02-03
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
- CVE-2013-2674HIGHCVSS 7.5EG 7.52020-02-03
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.
- CVE-2013-2676HIGHCVSS 7.5EG 7.52020-02-04
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.
- CVE-2013-2683MEDIUMCVSS 5.3EG 5.32020-02-06
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.
- CVE-2013-2737MEDIUMCVSS v2 5.0EG 5.02013-05-16
A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to obtain sensitive information via unspecified vectors.
- CVE-2013-2744MEDIUMCVSS v2 5.0EG 5.02013-04-02
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
- CVE-2013-2848MEDIUMCVSS v2 5.0EG 5.02013-05-22
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
- CVE-2013-2879MEDIUMCVSS v2 5.8EG 5.82013-07-10
Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for sign-in and subsequent sync operations, which makes it easier for remote attackers to condu…
- CVE-2013-2976LOWCVSS v2 1.9EG 1.92013-08-21
The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive infor…
- CVE-2013-2985MEDIUMCVSS v2 4.0EG 4.02013-07-03
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-201…
- CVE-2013-2987MEDIUMCVSS v2 4.0EG 4.02013-07-03
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-201…
- CVE-2013-2998LOWCVSS v2 3.5EG 3.52014-05-26
frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code.
- CVE-2013-3018MEDIUMCVSS 5.3EG 5.32018-05-24
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrate…
- CVE-2013-3020MEDIUMCVSS v2 4.0EG 4.02013-07-03
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-201…
- CVE-2013-3023HIGHCVSS 8.1EG 8.12018-05-24
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. …
- CVE-2013-3040MEDIUMCVSS v2 5.0EG 5.02013-08-16
IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-forc…
- CVE-2013-3070HIGHCVSS 7.5EG 7.52019-11-14
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
- CVE-2013-3076MEDIUMCVSS v2 4.9EG 4.92013-04-22
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to th…
- CVE-2013-3137MEDIUMCVSS v2 4.3EG 4.32013-09-11
Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disclosure Vulnerability."
- CVE-2013-3160MEDIUMCVSS v2 5.0EG 5.02013-09-11
Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, relat…
- CVE-2013-3185MEDIUMCVSS v2 5.0EG 5.02013-08-14
Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allows remote attackers to obtain sensitive information about the service acc…
- CVE-2013-3210MEDIUMCVSS v2 5.0EG 5.02013-04-19
Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.
- CVE-2013-3222MEDIUMCVSS v2 4.9EG 4.92013-04-22
The vcc_recvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvf…
- CVE-2013-3223MEDIUMCVSS v2 4.9EG 4.92013-04-22
The ax25_recvmsg function in net/ax25/af_ax25.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or rec…
- CVE-2013-3224MEDIUMCVSS v2 4.9EG 4.92013-04-22
The bt_sock_recvmsg function in net/bluetooth/af_bluetooth.c in the Linux kernel before 3.9-rc7 does not properly initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a…
- CVE-2013-3225MEDIUMCVSS v2 4.9EG 4.92013-04-22
The rfcomm_sock_recvmsg function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a craft…
- CVE-2013-3226MEDIUMCVSS v2 4.9EG 4.92013-04-22
The sco_sock_recvmsg function in net/bluetooth/sco.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg …
- CVE-2013-3227MEDIUMCVSS v2 4.9EG 4.92013-04-22
The caif_seqpkt_recvmsg function in net/caif/caif_socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted re…
- CVE-2013-3228MEDIUMCVSS v2 4.9EG 4.92013-04-22
The irda_recvmsg_dgram function in net/irda/af_irda.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg…
- CVE-2013-3229MEDIUMCVSS v2 4.9EG 4.92013-04-22
The iucv_sock_recvmsg function in net/iucv/af_iucv.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg …
- CVE-2013-3230MEDIUMCVSS v2 4.9EG 4.92013-04-22
The l2tp_ip6_recvmsg function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.9-rc7 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg…
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →