CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.— MITRE CWE catalog
11,183 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 5 of 224
- CVE-2007-6043HIGHCVSS v2 7.1EG 7.12007-11-20
The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward se…
- CVE-2007-6095MEDIUMCVSS v2 4.0EG 4.02007-11-22
The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT Traversal is employed, does not properly perform user registration and message distribution, which might allow remote authenticated users to rece…
- CVE-2007-6150LOWCVSS v2 2.1EG 2.12007-11-30
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection…
- CVE-2007-6161MEDIUMCVSS v2 5.0EG 5.02007-11-29
index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search action, which reveals the path.
- CVE-2007-6190LOWCVSS v2 3.5EG 3.52007-11-30
The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPho…
- CVE-2007-6193MEDIUMCVSS v2 5.0EG 5.02007-11-30
The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as…
- CVE-2007-6197MEDIUMCVSS v2 5.0EG 5.02007-12-01
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.
- CVE-2007-6206LOWCVSS v2 2.1EG 2.12007-12-04
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, w…
- CVE-2007-6221HIGHCVSS v2 7.8EG 7.82007-12-04
TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained sole…
- CVE-2007-6249LOWCVSS v2 2.1EG 2.12007-12-15
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive info…
- CVE-2007-6283MEDIUMCVSS v2 4.9EG 4.92007-12-18
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
- CVE-2007-6286MEDIUMCVSS v2 4.3EG 4.32008-02-12
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one o…
- CVE-2007-6405MEDIUMCVSS v2 6.4EG 6.42007-12-17
Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (…
- CVE-2007-6408MEDIUMCVSS v2 5.0EG 5.02007-12-17
IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easi…
- CVE-2007-6417HIGHCVSS v2 7.2EG 7.22007-12-18
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a deni…
- CVE-2007-6418LOWCVSS v2 2.1EG 2.12007-12-18
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.
- CVE-2007-6476MEDIUMCVSS v2 5.0EG 5.02007-12-20
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.
- CVE-2007-6502MEDIUMCVSS v2 5.5EG 5.52007-12-20
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP req…
- CVE-2007-6512MEDIUMCVSS v2 5.0EG 5.02007-12-21
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.
- CVE-2007-6513MEDIUMCVSS v2 4.3EG 4.32007-12-21
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
- CVE-2007-6514MEDIUMCVSS v2 4.3EG 4.32007-12-21
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is no…
- CVE-2007-6524HIGHCVSS v2 7.8EG 7.82007-12-24
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta,…
- CVE-2007-6536MEDIUMCVSS v2 6.8EG 6.82007-12-27
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier for remote attacke…
- CVE-2007-6606MEDIUMCVSS v2 5.0EG 5.02007-12-31
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
- CVE-2007-6607MEDIUMCVSS v2 5.0EG 5.02007-12-31
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals the path in various …
- CVE-2007-6660MEDIUMCVSS v2 5.0EG 5.02008-01-04
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain year and month parameters, which reveals the path in variou…
- CVE-2007-6702MEDIUMCVSS v2 5.0EG 5.02008-03-04
goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerabi…
- CVE-2007-6744LOWCVSS v2 2.1EG 2.12012-01-19
Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information …
- CVE-2008-0041MEDIUMCVSS v2 5.0EG 5.02008-02-12
Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running Parental Controls.
- CVE-2008-0050MEDIUMCVSS v2 5.0EG 5.02008-03-18
CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.
- CVE-2008-0052MEDIUMCVSS v2 6.8EG 6.82008-03-18
CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.
- CVE-2008-0082HIGHCVSS v2 10.0EG 10.02008-08-13
An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establi…
- CVE-2008-0085MEDIUMCVSS v2 5.0EG 5.02008-07-08
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initi…
- CVE-2008-0136MEDIUMCVSS v2 5.0EG 5.02008-01-08
Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.
- CVE-2008-0191MEDIUMCVSS v2 5.0EG 5.02008-01-10
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
- CVE-2008-0195MEDIUMCVSS v2 5.0EG 5.02008-01-10
WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.
- CVE-2008-0249MEDIUMCVSS v2 5.0EG 5.02008-01-12
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only b…
- CVE-2008-0297MEDIUMCVSS v2 5.0EG 5.02008-01-16
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.
- CVE-2008-0367MEDIUMCVSS v2 5.0EG 5.02008-01-19
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to condu…
- CVE-2008-0395MEDIUMCVSS v2 5.0EG 5.02008-01-23
Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.
- CVE-2008-0420HIGHCVSS v2 9.3EG 9.32008-02-12
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote atta…
- CVE-2008-0589MEDIUMCVSS v2 4.9EG 4.92008-02-05
The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.
- CVE-2008-0593MEDIUMCVSS v2 4.3EG 4.32008-02-09
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin …
- CVE-2008-0598MEDIUMCVSS v2 4.9EG 4.92008-06-30
Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary.
- CVE-2008-0636MEDIUMCVSS v2 5.0EG 5.02008-02-12
Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information.
- CVE-2008-0655CRITICALCVSS 8.8EG 9.8⚠ KEV2008-02-07
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
- CVE-2008-0662HIGHCVSS 7.8EG 7.82008-02-08
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to…
- CVE-2008-0736MEDIUMCVSS v2 5.0EG 5.02008-02-13
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.
- CVE-2008-0784MEDIUMCVSS v2 5.0EG 5.02008-02-14
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
- CVE-2008-0863MEDIUMCVSS v2 5.0EG 5.02008-02-21
BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks.
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →