Vulnerabilities > Missing Encryption of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2017-08-05 CVE-2017-9854 Missing Encryption of Sensitive Data vulnerability in SMA products
An issue was discovered in SMA Solar Technology products.
network
low complexity
sma CWE-311
critical
9.8
2017-07-11 CVE-2017-7729 Missing Encryption of Sensitive Data vulnerability in Ismartalarm Cubeone Firmware
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
network
low complexity
ismartalarm CWE-311
7.5
2017-07-07 CVE-2017-7406 Missing Encryption of Sensitive Data vulnerability in Dlink Dir-615 20.12Ptb01
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages.
network
low complexity
dlink CWE-311
critical
9.8
2017-06-13 CVE-2017-9604 Missing Encryption of Sensitive Data vulnerability in KDE Kmail and Messagelib
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
kde CWE-311
7.5
2017-05-18 CVE-2017-9045 Missing Encryption of Sensitive Data vulnerability in Google I/O 2017 5.0.3
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.
network
high complexity
google CWE-311
5.9
2017-05-18 CVE-2017-8769 Missing Encryption of Sensitive Data vulnerability in Whatsapp
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted.
low complexity
whatsapp CWE-311
4.6
2017-05-12 CVE-2017-7485 Missing Encryption of Sensitive Data vulnerability in Postgresql
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server.
network
high complexity
postgresql CWE-311
5.9
2017-04-25 CVE-2017-8221 Missing Encryption of Sensitive Data vulnerability in Wificam Wireless IP Camera (P2P) Firmware
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
wificam CWE-311
7.5
2017-04-24 CVE-2017-5042 Missing Encryption of Sensitive Data vulnerability in multiple products
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
low complexity
google redhat debian CWE-311
5.7
2017-03-05 CVE-2017-6445 Missing Encryption of Sensitive Data vulnerability in Openelec 6.0.3/7.0.1
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates.
network
high complexity
openelec CWE-311
8.1