High severity7.8NVD Advisory· Published Jul 8, 2019· Updated Jun 17, 2026
CVE-2019-12171
CVE-2019-12171
Description
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.
Affected products
3- cpe:2.3:a:dropbox:dropbox:71.4.108.0:*:*:*:*:desktop:*:*
- Dropbox/Dropbox desktop applicationdescription
- Range: = 71.4.108.0
Patches
Vulnerability mechanics
References
2- drive.google.com/opennvdExploitThird Party Advisory
- drive.google.com/opennvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.