CWE-1258
12 CVEs • Abstraction: Base
Exposure of Sensitive System Information Due to Uncleared Debug Information
The hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.
CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. |
1Canonical 1Ubuntu Desktop Provision Jun 17, 2026 Apr 9, 2026 2.7 LOW· v4 9.1 CRITICAL· v3 N/A· v2 In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could i...Show more |
In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credential...Show more |
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnera...Show more |
1Dell 112Dss 8440 Firmware Emc Nx440 FirmwareEmc Storage Nx3240 Firmware+109 moreJun 17, 2026 Sep 25, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Informati...Show more |
Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Clic...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 May 30, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or se...Show more |
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_mem...Show more |
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Ne...Show more |
Exposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. |
1Slack Morphism Project 1Slack Morphism Jun 17, 2026 Oct 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 wh...Show more |
1Slack Morphism Project 1Slack Morphism Jun 17, 2026 Jul 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug logs. Stricter and more secure debug formatting was introduced in v0.41...Show more |