An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access
An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access da
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside
An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of
An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access d
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC fil
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain s
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory addr
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.p
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pa
Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local
Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keyst
An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass opera
An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating syste
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to acces
An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application
An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application
The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for
fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-befor
In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linu
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potent
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be rea
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows R
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the p
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to vie
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwg
In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are no
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data
An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside o
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data
An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outsi
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resu
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper acc
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started