Vulnerabilities > Improper Cross-boundary Removal of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2020-12-09 CVE-2020-26965 Improper Cross-boundary Removal of Sensitive Data vulnerability in Mozilla Firefox
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password.
network
low complexity
mozilla CWE-212
6.5
2020-11-12 CVE-2020-8696 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel netapp fedoraproject debian CWE-212
5.5
2020-10-05 CVE-2020-25635 Improper Cross-boundary Removal of Sensitive Data vulnerability in Redhat Ansible 2.10.1
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed.
local
low complexity
redhat CWE-212
5.5
2020-09-23 CVE-2020-14370 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5.
network
high complexity
podman-project redhat fedoraproject CWE-212
5.3
2020-09-14 CVE-2020-11684 Improper Cross-boundary Removal of Sensitive Data vulnerability in Linux4Sam At91Bootstrap
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component.
network
low complexity
linux4sam CWE-212
critical
9.1
2020-08-11 CVE-2020-13179 Improper Cross-boundary Removal of Sensitive Data vulnerability in Teradici Graphics Agent and Pcoip Standard Agent
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single sign-on procedure.
local
low complexity
teradici CWE-212
5.5
2020-04-14 CVE-2020-11740 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests.
local
low complexity
xen debian fedoraproject opensuse CWE-212
5.5
2020-04-08 CVE-2019-20637 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
7.5
2020-04-01 CVE-2020-9780 Improper Cross-boundary Removal of Sensitive Data vulnerability in Apple Ipados and Iphone OS
The issue was resolved by clearing application previews when content is deleted.
local
low complexity
apple CWE-212
3.3
2020-02-27 CVE-2020-3874 Improper Cross-boundary Removal of Sensitive Data vulnerability in Apple Iphone OS
An issued existed in the naming of screenshots.
network
low complexity
apple CWE-212
5.3