An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its pe
An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read dat
An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a l
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious a
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable
An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KN
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including pa
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to o
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows l
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating syst
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass opera
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside
An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outs
An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access
A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated us
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves the "Windows Securi
An issue was discovered in certain Apple products. Transporter before 1.9.2 is affected. The issue involves the "iTMSTra
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "WiFi" compo
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a mali
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read proce
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers
An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to acces
An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access da
An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access da
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automati
In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to g
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users
An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure ap
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started