Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2017-05-11 CVE-2017-8851 Cleartext Transmission of Sensitive Information vulnerability in Oneplus Oxygenos
An issue was discovered on OnePlus One and X devices.
network
high complexity
oneplus CWE-319
5.9
2017-05-11 CVE-2017-8850 Cleartext Transmission of Sensitive Information vulnerability in Oneplus Oxygenos
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.
network
high complexity
oneplus CWE-319
5.9
2017-04-24 CVE-2017-3305 Cleartext Transmission of Sensitive Information vulnerability in multiple products
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API).
network
high complexity
oracle debian CWE-319
5.3
2017-04-02 CVE-2017-2412 Cleartext Transmission of Sensitive Information vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
high complexity
apple CWE-319
5.9
2017-03-17 CVE-2017-3815 Cleartext Transmission of Sensitive Information vulnerability in Cisco Telepresence Server Software 4.2(4.17)/4.2(4.18)/4.2(4.19)
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints.
network
low complexity
cisco CWE-319
5.3
2017-03-17 CVE-2017-6370 Cleartext Transmission of Sensitive Information vulnerability in Typo3 7.6.15
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
network
low complexity
typo3 CWE-319
5.3
2017-03-09 CVE-2017-6432 Cleartext Transmission of Sensitive Information vulnerability in Dahuasecurity NVR Firmware 3.210.0001.10
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices.
network
high complexity
dahuasecurity CWE-319
8.1
2017-03-02 CVE-2017-6410 Cleartext Transmission of Sensitive Information vulnerability in KDE Kdelibs
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
local
low complexity
kde CWE-319
5.5
2017-02-27 CVE-2017-6341 Cleartext Transmission of Sensitive Information vulnerability in Dahuasecurity Camera Firmware, NVR Firmware and Smartpss Firmware
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to obtain sensitive information by sniffing the network, a different vulnerability than CVE-2013-6117.
network
high complexity
dahuasecurity CWE-319
5.9
2008-12-19 CVE-2008-4122 Cleartext Transmission of Sensitive Information vulnerability in Joomla Joomla! 1.5.8
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
network
low complexity
joomla CWE-319
7.5