CWE-316
Cleartext Storage of Sensitive Information in Memory
VariantDraft
Description
The product stores sensitive information in cleartext in memory.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (42)
page 3 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23349 | Low | 0.14 | 2.2 | 0.00 | Mar 22, 2024 | Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into… | ||
| CVE-2014-2366 | 0.00 | — | 0.01 | Jul 19, 2014 | upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code. |
- risk 0.14cvss 2.2epss 0.00
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into…
- CVE-2014-2366Jul 19, 2014risk 0.00cvss —epss 0.01
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.