Vulnerabilities (CVE)

Filtered by CWE-200
Total 8276 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-3819 1 53x11 1 Wow Server Status 2025-04-11 5.0 MEDIUM N/A
WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files.
CVE-2010-1407 1 Apple 2 Iphone Os, Ipod Touch 2025-04-11 4.3 MEDIUM N/A
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.
CVE-2013-0095 1 Microsoft 1 Office 2025-04-11 5.0 MEDIUM N/A
Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
CVE-2012-4511 1 Gnome 1 Libsocialweb 2025-04-11 5.8 MEDIUM N/A
services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.
CVE-2013-1923 1 Linux-nfs 1 Nfs-utils 2025-04-11 3.2 LOW N/A
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
CVE-2011-0636 1 Nvidia 1 Cuda Toolkit 2025-04-11 2.1 LOW N/A
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.
CVE-2012-0328 1 Janetter 1 Janetter 2025-04-11 5.0 MEDIUM N/A
Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.
CVE-2012-1960 1 Mozilla 3 Firefox, Seamonkey, Thunderbird 2025-04-11 5.0 MEDIUM N/A
The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation.
CVE-2012-4846 1 Ibm 1 Lotus Notes 2025-04-11 4.3 MEDIUM N/A
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.
CVE-2013-3959 1 Siemens 2 Simatic Pcs7, Wincc 2025-04-11 4.0 MEDIUM N/A
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.
CVE-2011-3697 1 Achievo 1 Achievo 2025-04-11 5.0 MEDIUM N/A
Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/graph/jpgraph/jpgraph_radar.php and certain other files.
CVE-2012-4390 1 Owncloud 2 Owncloud, Owncloud Server 2025-04-11 4.0 MEDIUM N/A
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors.
CVE-2011-3708 1 Automne-cms 1 Automne 2025-04-11 5.0 MEDIUM N/A
Automne 4.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/page-redirect-info.php.
CVE-2012-5916 1 Neocrome 1 Seditio 2025-04-11 5.0 MEDIUM N/A
Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.
CVE-2013-4999 1 Phpmyadmin 1 Phpmyadmin 2025-04-11 5.0 MEDIUM N/A
phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.
CVE-2011-3787 1 Nick Korbel 1 Phpscheduleit 2025-04-11 5.0 MEDIUM N/A
phpScheduleIt 1.2.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/schedule.template.php and certain other files.
CVE-2013-6330 1 Ibm 1 Websphere Application Server 2025-04-11 3.5 LOW N/A
IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVE-2010-2975 1 Cisco 1 Unified Wireless Network Solution Software 2025-04-11 2.1 LOW N/A
Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544.
CVE-2011-1246 1 Microsoft 6 Internet Explorer, Windows 7, Windows Server 2003 and 3 more 2025-04-11 4.3 MEDIUM N/A
Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."
CVE-2011-3700 1 Anelectron 1 Advanced Electron Forum 2025-04-11 5.0 MEDIUM N/A
Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php.