The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in uninten
Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4,
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4,
The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive info
The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkin
Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted M
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi
The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an i
The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave featu
A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Bluetooth" compone
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for An
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp"
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FIL
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFString" c
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "QuickTime"
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "UIKit" component
Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data t
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vector
BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access loc
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that a
Huawei Hilink APP Versions earlier before 5.0.25.306 has an information leak vulnerability. An attacker may trick a user
Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have
HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability. An attacker could exploit it to do
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B1
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulne
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer acce
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Sup
An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started