Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2020-5274

Published Mar 30, 2020

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12446

Published Mar 10, 2020

An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10097

Published Mar 5, 2020

An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information co…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19993

Published Feb 26, 2020

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnerability were discovered. A user, even with no authentication…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9351

Published Feb 23, 2020

An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4583

Published Feb 20, 2020

IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6189

Published Feb 12, 2020

Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related infor…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-4636

Published Jan 28, 2020

IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8161

Published Jan 27, 2020

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7231

Published Jan 19, 2020

Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19806

Published Dec 30, 2019

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. Th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19342

Published Dec 19, 2019

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0404

Published Dec 11, 2019

SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-16768

Published Dec 5, 2019

In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServi…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-13697

Published Nov 25, 2019

Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6879

Published Nov 22, 2019

The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4570

Published Nov 22, 2019

IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 1…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6122

Published Nov 6, 2019

A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email ad…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-4512

Published Oct 9, 2019

IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.

CVSS 4.3 · Medium

CVE-2019-4441

Published Oct 3, 2019

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12156

Published Oct 2, 2019

Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource vers…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3730

Published Sep 30, 2019

RSA BSAFE Micro Edition Suite versions prior to 4.1.6.3 (in 4.1.x) and prior to 4.4 (in 4.2.x and 4.3.x), are vulnerable to an Information Exposure Through an Error Message vulner…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15032

Published Sep 19, 2019

Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obt…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 501-525 of 574 CVEsPage 21 of 23