Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2019-12-02 CVE-2012-5562 Cleartext Transmission of Sensitive Information vulnerability in Redhat Satellite
rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite
low complexity
redhat CWE-319
6.5
2019-12-02 CVE-2019-12503 Cleartext Transmission of Sensitive Information vulnerability in Inateck Bcst-60 Firmware
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks.
network
low complexity
inateck CWE-319
critical
9.8
2019-12-02 CVE-2019-12388 Cleartext Transmission of Sensitive Information vulnerability in Anviz Firmware
Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.
network
low complexity
anviz CWE-319
7.5
2019-11-30 CVE-2019-19463 Cleartext Transmission of Sensitive Information vulnerability in Huami MI FIT 4.0.10
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
network
low complexity
huami CWE-319
5.3
2019-11-21 CVE-2019-16545 Cleartext Transmission of Sensitive Information vulnerability in Qmetry Jenkins Qmetry for Jira
Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
network
low complexity
qmetry CWE-319
6.5
2019-11-20 CVE-2012-1257 Cleartext Transmission of Sensitive Information vulnerability in Pidgin 2.10.0
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
local
low complexity
pidgin CWE-319
5.5
2019-11-14 CVE-2019-3640 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Data Loss Prevention
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
network
low complexity
mcafee CWE-319
6.5
2019-11-12 CVE-2010-4177 Cleartext Transmission of Sensitive Information vulnerability in multiple products
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
local
low complexity
oracle fedoraproject CWE-319
5.5
2019-11-11 CVE-2019-18852 Cleartext Transmission of Sensitive Information vulnerability in Dlink products
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign.
network
low complexity
dlink CWE-319
critical
9.8
2019-11-06 CVE-2019-18800 Cleartext Transmission of Sensitive Information vulnerability in Rakuten Viber
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted.
network
low complexity
rakuten CWE-319
8.8