CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
8,658 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 66 of 174
- CVE-2018-6008HIGHCVSS 7.5EG 7.52018-01-29
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
- CVE-2018-6014MEDIUMCVSS 6.5EG 6.52018-01-23
Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a …
- CVE-2018-6015HIGHCVSS 7.5EG 7.52018-01-26
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading o…
- CVE-2018-6035HIGHCVSS 8.8EG 8.82018-09-25
Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.
- CVE-2018-6037MEDIUMCVSS 6.5EG 6.52018-09-25
Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.
- CVE-2018-6045MEDIUMCVSS 6.5EG 6.52018-09-25
Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.
- CVE-2018-6052MEDIUMCVSS 4.3EG 4.32018-09-25
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.
- CVE-2018-6053LOWCVSS 3.3EG 3.32018-09-25
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
- CVE-2018-6066MEDIUMCVSS 6.5EG 6.52018-11-14
Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6075MEDIUMCVSS 6.5EG 6.52018-11-14
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
- CVE-2018-6077MEDIUMCVSS 6.5EG 6.52018-11-14
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6079MEDIUMCVSS 6.5EG 6.52018-11-14
Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6082MEDIUMCVSS 4.7EG 4.72018-11-14
Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
- CVE-2018-6093MEDIUMCVSS 6.5EG 6.52019-01-09
Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6095MEDIUMCVSS 6.5EG 6.52018-12-04
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
- CVE-2018-6099MEDIUMCVSS 6.5EG 6.52018-12-04
A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
- CVE-2018-6109MEDIUMCVSS 6.5EG 6.52019-01-09
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system witho…
- CVE-2018-6117MEDIUMCVSS 6.5EG 6.52019-01-09
Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2018-6134MEDIUMCVSS 6.5EG 6.52019-06-27
Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.
- CVE-2018-6137MEDIUMCVSS 6.5EG 6.52019-01-09
CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6147MEDIUMCVSS 5.5EG 5.52019-01-09
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
- CVE-2018-6150MEDIUMCVSS 6.5EG 6.52019-06-27
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6159MEDIUMCVSS 6.5EG 6.52019-06-27
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2018-6164MEDIUMCVSS 6.5EG 6.52019-01-09
Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6168MEDIUMCVSS 6.5EG 6.52019-06-27
Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2018-6177MEDIUMCVSS 4.3EG 4.32019-06-27
Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2018-6179MEDIUMCVSS 6.5EG 6.52019-01-09
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file syste…
- CVE-2018-6188HIGHCVSS 7.5EG 7.52018-02-05
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as dem…
- CVE-2018-6234MEDIUMCVSS 5.5EG 5.52018-05-25
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL …
- CVE-2018-6239MEDIUMCVSS 5.5EG 5.52019-04-12
NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may access the contents of cached information in an unauthorized manner, which may lead to information disclosure. The updates a…
- CVE-2018-6246MEDIUMCVSS 5.3EG 5.32018-05-10
In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Informat…
- CVE-2018-6254LOWCVSS 3.3EG 3.32018-05-10
In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. A…
- CVE-2018-6259LOWCVSS 2.5EG 2.52018-08-31
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possi…
- CVE-2018-6260MEDIUMCVSS 5.5EG 5.52018-11-13
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This is not a network or remote a…
- CVE-2018-6262LOWCVSS 2.5EG 2.52018-10-02
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.
- CVE-2018-6266MEDIUMCVSS 5.5EG 5.52018-11-27
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
- CVE-2018-6293HIGHCVSS 7.5EG 7.52018-02-13
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
- CVE-2018-6412HIGHCVSS 7.5EG 7.52018-01-31
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
- CVE-2018-6460HIGHCVSS 7.5EG 7.52018-01-31
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated atta…
- CVE-2018-6470MEDIUMCVSS 5.3EG 5.32018-02-01
Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
- CVE-2018-6487CRITICALCVSS 9.8EG 7.52018-02-20
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of informat…
- CVE-2018-6526MEDIUMCVSS 5.3EG 5.32018-02-02
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.
- CVE-2018-6559LOWCVSS 3.3EG 3.32018-10-26
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
- CVE-2018-6591MEDIUMCVSS 5.3EG 5.32018-02-19
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have …
- CVE-2018-6596CRITICALCVSS 9.1EG 9.12018-02-03
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
- CVE-2018-6608MEDIUMCVSS 4.3EG 4.32018-03-28
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
- CVE-2018-6610HIGHCVSS 7.5EG 7.52018-02-05
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
- CVE-2018-6672MEDIUMCVSS 5.7EG 6.52018-06-15
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.
- CVE-2018-6790MEDIUMCVSS 5.3EG 5.32018-02-07
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of a…
- CVE-2018-6806MEDIUMCVSS 6.5EG 6.52018-02-07
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., m…
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →