Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2019-11-21 CVE-2019-16545 Cleartext Transmission of Sensitive Information vulnerability in Qmetry Jenkins Qmetry for Jira
Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
network
low complexity
qmetry CWE-319
6.5
2019-11-20 CVE-2012-1257 Cleartext Transmission of Sensitive Information vulnerability in Pidgin 2.10.0
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
local
low complexity
pidgin CWE-319
2.1
2019-11-14 CVE-2019-3640 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Data Loss Prevention
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
network
low complexity
mcafee CWE-319
6.5
2019-11-12 CVE-2010-4177 Cleartext Transmission of Sensitive Information vulnerability in multiple products
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
local
low complexity
oracle fedoraproject CWE-319
2.1
2019-11-11 CVE-2019-18852 Cleartext Transmission of Sensitive Information vulnerability in Dlink products
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign.
network
low complexity
dlink CWE-319
critical
10.0
2019-11-06 CVE-2019-18800 Cleartext Transmission of Sensitive Information vulnerability in Rakuten Viber
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted.
network
rakuten CWE-319
4.3
2019-10-29 CVE-2019-6846 Cleartext Transmission of Sensitive Information vulnerability in Schneider-Electric products
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.
4.3
2019-10-29 CVE-2019-6845 Cleartext Transmission of Sensitive Information vulnerability in Schneider-Electric products
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.
network
low complexity
schneider-electric CWE-319
5.0
2019-10-22 CVE-2019-12967 Cleartext Transmission of Sensitive Information vulnerability in Themooltipass Moolticute
Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
4.3
2019-10-17 CVE-2019-15626 Cleartext Transmission of Sensitive Information vulnerability in Trendmicro Deep Security 10.0/11.0/12.0
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text.
4.3