Vulnerabilities > Improper Cross-boundary Removal of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2021-33080 Improper Cross-boundary Removal of Sensitive Data vulnerability in Intel products
Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to potentially enable information disclosure or escalation of privilege via physical access.
low complexity
intel CWE-212
6.8
2022-05-12 CVE-2021-33082 Improper Cross-boundary Removal of Sensitive Data vulnerability in Intel products
Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.
low complexity
intel CWE-212
4.6
2022-03-31 CVE-2022-24798 Improper Cross-boundary Removal of Sensitive Data vulnerability in Internet Routing Registry Daemon Project Internet Routing Registry Daemon 4.2.0/4.2.1/4.2.2
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format.
7.5
2022-03-11 CVE-2021-26341 Improper Cross-boundary Removal of Sensitive Data vulnerability in AMD products
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
local
low complexity
amd CWE-212
6.5
2022-03-03 CVE-2021-3602 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An information disclosure flaw was found in Buildah, when building containers using chroot isolation.
local
low complexity
buildah-project redhat CWE-212
5.5
2022-03-01 CVE-2022-24719 Improper Cross-boundary Removal of Sensitive Data vulnerability in Fluture-Node Project Fluture-Node 4.0.0/4.0.1
Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture.
network
low complexity
fluture-node-project CWE-212
6.1
2022-02-15 CVE-2022-25187 Improper Cross-boundary Removal of Sensitive Data vulnerability in Jenkins Support Core
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
network
low complexity
jenkins CWE-212
6.5
2022-02-11 CVE-2022-23633 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
Action Pack is a framework for handling and responding to web requests.
network
high complexity
rubyonrails debian CWE-212
5.9
2022-02-09 CVE-2022-22779 Improper Cross-boundary Removal of Sensitive Data vulnerability in Keybase
The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user.
network
high complexity
keybase CWE-212
3.7
2022-02-04 CVE-2022-23605 Improper Cross-boundary Removal of Sensitive Data vulnerability in Wire Wire-Webapp
Wire webapp is a web client for the wire messaging protocol.
local
low complexity
wire CWE-212
2.3