CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,184 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 13 of 224
- CVE-2010-0464MEDIUMCVSS v2 5.0EG 5.02010-01-29
Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by loggi…
- CVE-2010-0488MEDIUMCVSS 6.5EG 6.52010-03-31
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Pos…
- CVE-2010-0494MEDIUMCVSS v2 4.3EG 4.32010-03-31
Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation w…
- CVE-2010-0523MEDIUMCVSS v2 5.0EG 5.02010-03-30
Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java …
- CVE-2010-0548MEDIUMCVSS v2 5.0EG 5.02010-02-04
Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unknown vectors that bypass Scan to Mailbox a…
- CVE-2010-0549MEDIUMCVSS v2 5.0EG 5.02010-02-04
Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory …
- CVE-2010-0551MEDIUMCVSS v2 5.0EG 5.02010-02-04
HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect authentication attempt, which includes sensitive memory in…
- CVE-2010-0563MEDIUMCVSS v2 5.0EG 5.02010-02-08
The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffi…
- CVE-2010-0572HIGHCVSS v2 7.1EG 7.12010-03-05
Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050.
- CVE-2010-0642MEDIUMCVSS v2 5.0EG 5.02010-02-17
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3…
- CVE-2010-0643MEDIUMCVSS v2 4.3EG 4.32010-02-18
Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client…
- CVE-2010-0644MEDIUMCVSS v2 4.3EG 4.32010-02-18
Google Chrome before 4.0.249.89, when a SOCKS 5 proxy server is configured, sends DNS queries directly, which allows remote DNS servers to obtain potentially sensitive information about the identity of a client user via request logging, as…
- CVE-2010-0648MEDIUMCVSS v2 4.3EG 4.32010-02-18
Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then rea…
- CVE-2010-0651MEDIUMCVSS v2 4.3EG 4.32010-02-18
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is mal…
- CVE-2010-0652MEDIUMCVSS v2 4.3EG 4.32010-02-18
Microsoft Internet Explorer permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive informa…
- CVE-2010-0653MEDIUMCVSS v2 4.3EG 4.32010-02-18
Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a c…
- CVE-2010-0654MEDIUMCVSS v2 4.3EG 4.32010-02-18
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect…
- CVE-2010-0656MEDIUMCVSS v2 4.3EG 4.32010-02-18
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information…
- CVE-2010-0660MEDIUMCVSS v2 5.0EG 5.02010-02-18
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via stan…
- CVE-2010-0663MEDIUMCVSS v2 5.0EG 5.02010-02-18
The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obtain potentially sens…
- CVE-2010-0670MEDIUMCVSS v2 5.0EG 5.02010-02-22
Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path for Joomla! via unknown vectors.
- CVE-2010-0750LOWCVSS v2 2.1EG 2.12010-04-06
pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.
- CVE-2010-0790LOWCVSS v2 2.1EG 2.12010-03-10
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name.
- CVE-2010-0808LOWCVSS v2 2.6EG 2.62010-10-13
Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, …
- CVE-2010-0826LOWCVSS v2 1.9EG 1.92010-04-05
The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid…
- CVE-2010-1007MEDIUMCVSS v2 5.0EG 5.02010-03-19
Unspecified vulnerability in the Power Extension Manager (ch_lightem) extension 1.0.34 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
- CVE-2010-1125MEDIUMCVSS v2 5.8EG 5.82010-03-26
The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form fiel…
- CVE-2010-1126MEDIUMCVSS v2 5.8EG 5.82010-03-26
The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
- CVE-2010-1138MEDIUMCVSS v2 5.0EG 5.02010-04-12
The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on …
- CVE-2010-1149LOWCVSS v2 2.1EG 2.12010-04-12
probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command o…
- CVE-2010-1230HIGHCVSS v2 10.0EG 10.02010-04-01
Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
- CVE-2010-1258MEDIUMCVSS v2 4.3EG 4.32010-08-11
Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vect…
- CVE-2010-1294LOWCVSS v2 2.1EG 2.12010-05-13
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.
- CVE-2010-1310MEDIUMCVSS v2 5.0EG 5.02010-04-08
Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other pages.
- CVE-2010-1384MEDIUMCVSS v2 4.3EG 4.32010-06-11
Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attack…
- CVE-2010-1388MEDIUMCVSS v2 4.3EG 4.32010-06-11
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary …
- CVE-2010-1393MEDIUMCVSS v2 4.3EG 4.32010-06-11
The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to discover sensitive URLs via an HREF attribute assoc…
- CVE-2010-1406MEDIUMCVSS v2 4.3EG 4.32010-06-11
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which a…
- CVE-2010-1407MEDIUMCVSS v2 4.3EG 4.32010-06-22
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a craf…
- CVE-2010-1432HIGHCVSS 7.5EG 7.52021-06-21
Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and inc…
- CVE-2010-1457MEDIUMCVSS v2 4.9EG 4.92010-05-12
Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message.
- CVE-2010-1636LOWCVSS v2 2.1EG 2.12010-06-08
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows l…
- CVE-2010-1796LOWCVSS v2 2.6EG 2.62010-07-30
The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keyst…
- CVE-2010-1800MEDIUMCVSS v2 5.0EG 5.02010-08-25
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.
- CVE-2010-1851MEDIUMCVSS v2 4.3EG 4.32010-05-07
Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTT…
- CVE-2010-1852MEDIUMCVSS v2 4.3EG 4.32010-05-07
Microsoft Internet Explorer, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product se…
- CVE-2010-1860MEDIUMCVSS v2 5.0EG 5.02010-05-07
The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an int…
- CVE-2010-1862MEDIUMCVSS v2 5.0EG 5.02010-05-07
The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call …
- CVE-2010-1864MEDIUMCVSS v2 5.0EG 5.02010-05-07
The addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call …
- CVE-2010-1907MEDIUMCVSS v2 4.3EG 4.32010-05-12
The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certai…
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →