Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability.
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cl
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. Th
IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to o
Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The sof
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (A
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" co
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Notes" component.
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" comp
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "NVIDIA Grap
An information disclosure vulnerability in the Qualcomm IPA driver. Product: Android. Versions: Android kernel. Android
In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient
In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to user
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information e
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Intel Graph
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Dr
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth"
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the loc
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable t
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote at
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-2
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote atta
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote
The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows
The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration
An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in Tinfoi
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensit
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sens
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier fo
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which all
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checkin
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started