Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,185 CVEs tagged with CWE-53256 Critical, 263 High, 719 Medium, 147 Low, 0 Unrated.

CVE-2018-15001

Published Dec 28, 2018

The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14995

Published Dec 28, 2018

The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fin…

CVSS 4.7 · Medium

CVE-2018-19863

Published Dec 22, 2018

An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15797

Published Dec 5, 2018

Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH dep…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19865

Published Dec 5, 2018

A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19786

Published Dec 5, 2018

HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism withou…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14700

Published Dec 3, 2018

Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "na…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16859

Published Nov 29, 2018

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plain…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1788

Published Nov 2, 2018

IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15763

Published Oct 5, 2018

Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with acce…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1264

Published Oct 5, 2018

Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache V…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16049

Published Oct 3, 2018

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive Data Disclosure in Sidekiq Log…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1768

Published Sep 26, 2018

IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in pla…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3828

Published Sep 19, 2018

Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryptio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3827

Published Sep 19, 2018

A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRA…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1223

Published Sep 17, 2018

Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1198

Published Sep 17, 2018

Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3776

Published Aug 12, 2018

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7754

Published Aug 10, 2018

The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree:…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,185 CVEsPage 44 of 48