VYPR

CWE-316

Cleartext Storage of Sensitive Information in Memory

VariantDraft

Description

The product stores sensitive information in cleartext in memory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (42)

page 3 of 3
  • CVE-2023-23349LowMar 22, 2024
    risk 0.14cvss 2.2epss 0.00

    Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into…

  • CVE-2014-2366Jul 19, 2014
    risk 0.00cvss —epss 0.01

    upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.