Vulnerabilities > Missing Encryption of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2017-10-19 CVE-2017-15609 Missing Encryption of Sensitive Data vulnerability in Octopus Deploy
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.
network
low complexity
octopus CWE-311
5.0
2017-08-25 CVE-2017-12817 Missing Encryption of Sensitive Data vulnerability in Kaspersky Internet Security 11.12.4.1622
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
network
low complexity
kaspersky CWE-311
5.0
2017-08-07 CVE-2017-9632 Missing Encryption of Sensitive Data vulnerability in Pdqinc products
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all versions, and ProTouch AutoGloss, all versions.
network
low complexity
pdqinc CWE-311
5.0
2017-08-05 CVE-2017-9854 Missing Encryption of Sensitive Data vulnerability in SMA products
An issue was discovered in SMA Solar Technology products.
network
low complexity
sma CWE-311
critical
9.8
2017-07-11 CVE-2017-7729 Missing Encryption of Sensitive Data vulnerability in Ismartalarm Cubeone Firmware
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
network
low complexity
ismartalarm CWE-311
5.0
2017-07-07 CVE-2017-7406 Missing Encryption of Sensitive Data vulnerability in Dlink Dir-615 20.12Ptb01
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages.
network
low complexity
dlink CWE-311
5.0
2017-06-13 CVE-2017-9604 Missing Encryption of Sensitive Data vulnerability in KDE Kmail and Messagelib
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
kde CWE-311
5.0
2017-05-18 CVE-2017-9045 Missing Encryption of Sensitive Data vulnerability in Google I/O 2017
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.
network
google CWE-311
4.3
2017-05-18 CVE-2017-8769 Missing Encryption of Sensitive Data vulnerability in Whatsapp
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted.
low complexity
whatsapp CWE-311
4.6
2017-05-12 CVE-2017-7485 Missing Encryption of Sensitive Data vulnerability in Postgresql
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server.
4.3