Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI devic
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default conf
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnera
Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive informati
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclos
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain v
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The is
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x bef
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to informatio
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. T
Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remo
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive informat
IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to informati
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing th
Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low ver
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged
HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier be
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive inform
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Suppo
Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.
The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obta
IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
A vulnerability has been identified in tasks, backend object generated for handling any action performed by the applicat
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOSurface"
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOAccelerat
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOKit" comp
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "IOAudioFami
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensiti
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves mishandling of deleti
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "iBooks" com
The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the
ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and
A Win32k information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages,
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows loc
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expo
In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.
In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropri
A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started