CWE-212
124 CVEs • Abstraction: Base
Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
CVEs (124)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ovirt Redhat2Ovirt VirtualizationNov 21, 2024 Jul 27, 2018 N/A· v4 6.6 MEDIUM· v3 3.5 LOW· v2 ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents...Show more |
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed fro...Show more |
1Image Processing Project 1Image Processing Apr 16, 2026 Feb 14, 2005 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed...Show more |
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages. |