CVE-2024-43189 – IBM Concert Software information disclosure
https://notcve.org/view.php?id=CVE-2024-43189
IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. • https://www.ibm.com/support/pages/node/7173596 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2021-3986 – Information Disclosure in janeczku/calibre-web
https://notcve.org/view.php?id=CVE-2021-3986
This vulnerability discloses private information and affects all versions prior to the fix. • https://github.com/janeczku/calibre-web/commit/6f5390ead5df9779ac81fadefffb476e03f93548 https://huntr.com/bounties/394af194-61a7-4e33-b373-877d4c766fca • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2024-46383
https://notcve.org/view.php?id=CVE-2024-46383
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext. • http://skyworth.com https://github.com/nitinronge91/Sensitive-Information-disclosure-via-SPI-flash-firmware-for-Hathway-router-CVE-2024-46383 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2017-13227
https://notcve.org/view.php?id=CVE-2017-13227
This could lead to information disclosure with no additional execution privileges needed. • https://source.android.com/security/bulletin/2018-06-01 •
CVE-2024-48967 – Life2000 ventilator and Service PC lack sufficient audit logging capabilities
https://notcve.org/view.php?id=CVE-2024-48967
An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01 • CWE-778: Insufficient Logging •