Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2019-0266 Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a … Hana Extended Application Services Mitigation only Fix from $1,9502019-02-15 CRITICAL 9.8 CVE-2019-4008 API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to … Api Connect after 2018.4.1.1 Fix from $2,3002019-02-07 MEDIUM 5.3 CVE-2017-1198 IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure… Bigfix Compliance after 1.9.91 Fix from $1,6002019-02-05 MEDIUM 6.5 CVE-2018-19014 Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files … Kappa Firmware Mitigation only Fix from $1,6002019-01-28 HIGH 7.5 CVE-2018-16889 Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files … Ceph after 13.2.4 Fix from $1,9502019-01-28 MEDIUM 5.5 CVE-2019-0021 On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be… Advanced Threat Prevention 5.0.4+ Fix from $1,6002019-01-15 HIGH 7.8 CVE-2019-0029 Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the … Advanced Threat Prevention 5.0.3+ Fix from $1,9502019-01-15 MEDIUM 5.5 CVE-2019-0004 On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critica… Advanced Threat Prevention 5.0.3+ Fix from $1,6002019-01-15 HIGH 7.8 CVE-2019-3500 aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to … Debian Linux Patch available Fix from $1,9502019-01-02 MEDIUM 5.5 CVE-2018-15001 The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a pa… V7 Firmware No fix yet Fix from $1,6002018-12-28 MEDIUM 5.9 CVE-2018-15004 The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a p… Canvas Firmware No fix yet Fix from $1,6002018-12-28 MEDIUM 5.5 CVE-2018-19863 An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data p… 1password Mitigation only Fix from $1,6002018-12-22 HIGH 8.8 CVE-2018-15797 Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when runn… Cloud Foundry Nfs Volume 1.2.5 / 1.5.4+ Fix from $1,9502018-12-05 HIGH 7.5 CVE-2018-19865 A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3. Qt 5.11.3+ Fix from $1,9502018-12-05 HIGH 8.1 CVE-2018-19786 HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from… Vault 1.0.0+ Fix from $1,9502018-12-05 HIGH 7.5 CVE-2018-14700 Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrie… 5n2 Firmware No fix yet Fix from $1,9502018-12-03 MEDIUM 5.9 CVE-2018-16095 In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails. System Management Module Firmware 1.06+ Fix from $1,6002018-11-27 CRITICAL 9.8 CVE-2018-17922 Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible withou… Circarlife Firmware 4.3.1+ Fix from $2,3002018-11-02 MEDIUM 5.5 CVE-2018-1876 IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installat… Robotic Process Automation With Automation Anywhere Patch available Fix from $1,6002018-11-02 HIGH 7.5 CVE-2018-17447 An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0… Netscaler Sd Wan 9.3.6 / 10.0.4+ Fix from $1,9502018-10-23 HIGH 8.8 CVE-2018-15763 Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application lo… Pivotal Container Service 1.2+ Fix from $1,9502018-10-05 CRITICAL 9.8 CVE-2018-1264 Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has ga… Cloud Foundry Log Cache 1.1.1+ Fix from $2,3002018-10-05 MEDIUM 6.5 CVE-2018-0504 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid Debian Linux 1.31.1+ Fix from $1,6002018-10-04 CRITICAL 9.8 CVE-2018-16049 An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive … GitLab 11.0.6 / 11.1.5+ Fix from $2,3002018-10-03 HIGH 7.8 CVE-2018-1768 IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an pa… Spectrum Protect Plus Patch available Fix from $1,9502018-09-26 HIGH 8.1 CVE-2018-3827 A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azu… Azure Repository after 6.2.4 Fix from $1,9502018-09-19 HIGH 7.5 CVE-2018-3828 Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception condit… Elastic Cloud Enterprise 1.1.4+ Fix from $1,9502018-09-19 HIGH 8.8 CVE-2018-1223 Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user … Cloud Foundry Container Runtime 0.14.0+ Fix from $1,9502018-09-17 HIGH 8.8 CVE-2018-1198 Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to … Pivotal Cloud Cache 1.3.1+ Fix from $1,9502018-09-17 MEDIUM 5.5 CVE-2018-6599 An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive in… Wonder Rc555l Firmware Mitigation only Fix from $1,6002018-08-29