CVE-2026-67383
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a netw
CVSS
6.5
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-209
Sin historial EPSS suficiente todavía.
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-663066.5 MED—
———Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.6hCVE-2026-696845.5 MED—
———Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.4hCVE-2026-695525.7 MED—
———Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.4hCVE-2026-692945.5 MED—
———Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.4hCVE-2026-688865.5 MED—
———Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.4hCVE-2026-118736.5 MED25.0%
——8An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.7d