CWE-311

High likelihood

Missing Encryption of Sensitive Data

Parent: CWE-693 - Protection Mechanism Failure

The product does not encrypt sensitive or critical information before storage or transmission.

508 vulnerabilities with CWE-311
CVE-2014-6274 HIGH
git-annex <5.20140919 - Info Disclosure
CVSS 7.5
CVE-2014-2379
Sensys Networks VSN240-F/VSN240-T <2.10.1/2.10.3 - Info Disclosure
CVE-2012-5474 MEDIUM
Red Hat OpenStack Platform <2.0 - Info Disclosure
CVSS 5.5
CVE-2012-1977
WellinTech KingSCADA 3.0 - Cleartext Password Storage in user.db
CVE-2011-3355 HIGH
evolution-data-server3 3.0.3-3.2.1 - Unauthenticated Sensitive Data Exposure via Non-SSL Connection
CVSS 7.3
CVE-2010-3299 MEDIUM
Ruby on Rails 2.3 - Info Disclosure
CVSS 6.5
CVE-2010-3292 MEDIUM
mailscanner <4.79.11-2 - Code Injection
CVSS 5.5
CVE-2007-4961 HIGH
Second Life - Unauthenticated Sensitive Data Exposure via Cleartext MD5 Hash in Login
CVSS 7.5
Details
Vulnerabilities 508
Exploit Likelihood High