VYPR

CWE-316

Cleartext Storage of Sensitive Information in Memory

VariantDraft

Description

The product stores sensitive information in cleartext in memory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (37)

page 2 of 2
  • CVE-2025-42888MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during runtime.This vulnerability has a high impact on confidentiality, with no impact on integrity and availability.

  • CVE-2022-33918MedOct 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user could potentially exploit this vulnerability and gain access to sensitive information.

  • CVE-2021-31989MedAug 25, 2021
    risk 0.34cvss 5.3epss 0.00

    A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.

  • CVE-2019-3733MedSep 30, 2019
    risk 0.32cvss 4.9epss 0.01

    RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could potentially exploit this vulnerability…

  • CVE-2025-65832MedDec 10, 2025
    risk 0.30cvss 4.6epss 0.00

    The mobile application insecurely handles information stored within memory. By performing a memory dump on the application after a user has logged out and terminated it, Wi-Fi credentials sent during the pairing process, JWTs used for authentication, and other sensitive details…

  • CVE-2025-4618MedNov 14, 2025
    risk 0.29cvss epss 0.00

    A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.

  • CVE-2024-49800MedFeb 6, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

  • CVE-2023-3762MedJul 19, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Intergard SGS 8.7.0. It has been classified as problematic. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information in memory. It is possible to initiate the attack remotely. The exploit has been disclosed…

  • CVE-2025-61713MedNov 18, 2025
    risk 0.27cvss 4.2epss 0.00

    A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow…

  • CVE-2024-35282MedSep 10, 2024
    risk 0.27cvss 4.2epss 0.00

    A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an unauthenticated attacker that has physical access to a jailbroken…

  • CVE-2024-39732MedJul 14, 2024
    risk 0.27cvss 4.1epss 0.00

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791.

  • CVE-2022-46141MedDec 12, 2023
    risk 0.27cvss 4.2epss 0.00

    A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in…

  • CVE-2022-29832LowNov 25, 2022
    risk 0.24cvss 3.7epss 0.01

    Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote unauthenticated attacker to disclose sensitive information.…

  • CVE-2025-48930LowMay 28, 2025
    risk 0.18cvss 2.8epss 0.00

    The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

  • CVE-2024-9203LowSep 26, 2024
    risk 0.16cvss 2.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached…

  • CVE-2023-23349LowMar 22, 2024
    risk 0.14cvss 2.2epss 0.00

    Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into…

  • CVE-2014-2366Jul 19, 2014
    risk 0.00cvss epss 0.01

    upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.