Show filters
253 Total Results
Displaying 71-80 of 253
Sort by:
Attacker Value
Unknown

CVE-2021-39032

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 213962.
Attacker Value
Unknown

CVE-2021-45449

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.
Attacker Value
Unknown

CVE-2022-20651

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view the credentials of other users of the shared device.
Attacker Value
Unknown

CVE-2021-45034

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.
Attacker Value
Unknown

CVE-2021-34797

Disclosure Date: January 04, 2022 (last updated February 23, 2025)
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.
Attacker Value
Unknown

CVE-2021-0997

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191086488
Attacker Value
Unknown

CVE-2021-0991

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752
Attacker Value
Unknown

CVE-2021-37861

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
Attacker Value
Unknown

CVE-2021-34800

Disclosure Date: November 25, 2021 (last updated February 23, 2025)
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147
Attacker Value
Unknown

CVE-2021-37036

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.