Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2019-11-25 CVE-2019-5848 Cleartext Storage of Sensitive Information vulnerability in Google Chrome
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google CWE-312
6.5
2019-11-15 CVE-2011-2916 Cleartext Storage of Sensitive Information vulnerability in Qtnx Project Qtnx 0.9
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file.
local
low complexity
qtnx-project CWE-312
2.1
2019-11-08 CVE-2008-7272 Cleartext Storage of Sensitive Information vulnerability in Getfiregpg Firegpg
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.
network
low complexity
getfiregpg CWE-312
5.0
2019-11-05 CVE-2019-8118 Cleartext Storage of Sensitive Information vulnerability in Magento
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.
network
low complexity
magento CWE-312
5.0
2019-10-29 CVE-2019-4314 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium BIG Data Intelligence 4.0
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
network
low complexity
ibm CWE-312
7.5
2019-10-28 CVE-2019-3636 Cleartext Storage of Sensitive Information vulnerability in Mcafee Total Protection
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.
local
low complexity
mcafee CWE-312
7.8
2019-10-16 CVE-2019-10453 Cleartext Storage of Sensitive Information vulnerability in Jenkins Delphix
Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-312
7.8
2019-10-16 CVE-2019-10452 Cleartext Storage of Sensitive Information vulnerability in Jenkins View26 Test-Reporting
Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10451 Cleartext Storage of Sensitive Information vulnerability in Jenkins Soasta Cloudtest
Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10450 Cleartext Storage of Sensitive Information vulnerability in Jenkins Elasticbox CI
Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-312
3.3