CWE:
 

Topic
Date
Author
High
Multiple D-Link Routers Cross Site Scripting / Information Disclosure
23.05.2014
Kyle Lovett
High
Multiple apps plain text storage in memory (FileZilla, iTunes, etc)
22.08.2012
Myo Soe


CVEMAP Search Results

CVE
Details
Description
2024-09-26
Waiting for details
CVE-2024-9203

Updating...
 

 
A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 6.10.1 is able to address this issue. It is recommended to upgrade the affected component.

 
2024-09-10
Waiting for details
CVE-2024-35282

Updating...
 

 
A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an unauthenticated attacker that has physical access to a jailbroken device to obtain cleartext passwords via keychain dump.

 
2024-07-14
Waiting for details
CVE-2024-39732

Updating...
 

 
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791.

 
2023-12-12
Waiting for details
CVE-2022-46141

Updating...
 

 
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.

 
2023-09-12
Waiting for details
CVE-2023-40724

Updating...
 

 
A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.

 
2023-07-19
Waiting for details
CVE-2023-3762

Updating...
 

 
A vulnerability was found in Intergard SGS 8.7.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information in memory. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-234447. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

 

 


Copyright 2024, cxsecurity.com

 

Back to Top