CVE-2021-39081 – IBM Cognos Analytics Mobile information disclosure
https://notcve.org/view.php?id=CVE-2021-39081
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Cognos Analytics Mobile para Android 1.1.14 utiliza algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. • https://www.ibm.com/support/pages/node/6555140 • CWE-319: Cleartext Transmission of Sensitive Information •
CVE-2024-12754 – AnyDesk Link Following Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2024-12754
This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. •
CVE-2024-47039 – OOB Read in the android.hardware.boot.IBootControl/default service
https://notcve.org/view.php?id=CVE-2024-47039
This could lead to local information disclosure with no additional execution privileges needed. • https://source.android.com/security/bulletin/pixel/2024-11-01 • CWE-125: Out-of-bounds Read •
CVE-2024-52361 – IBM Storage Defender - Resiliency Service information disclosure
https://notcve.org/view.php?id=CVE-2024-52361
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access to the pod. • https://www.ibm.com/support/pages/node/7178587 • CWE-256: Plaintext Storage of a Password •
CVE-2023-50956 – IBM Storage Defender - Resiliency Service information disclosure
https://notcve.org/view.php?id=CVE-2023-50956
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text. • https://www.ibm.com/support/pages/node/7178587 • CWE-256: Plaintext Storage of a Password •