Draft in the CWE catalog Β· 22 CVEs mapped
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
β‘ A backup logging blunder can expose your encryption keys! MyHoard versions 1.0.1 through 1.2.9 might accidentally spill critical secrets in their logs β like leaving the front door wide open during a home renovation. π‘π Think of MyHoard as a vault that stores your valuable documents. If that vault logs the combination on a sticky note and leaves it out in the open, anyone could waltz in and take what they want! This oversight could lead to an attacker accessing your MySQL backups and sensitive data β with your encryption keys laid bare, they could decrypt everything and wreak havoc. Imagine losing your most critical information because someone snooped at those logs!
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.