CVE-2019-12171
Summary
| CVE | CVE-2019-12171 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-08 13:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process. |
Risk And Classification
Problem Types: CWE-312 | CWE-522
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cloud Storage for Work and Home - Google Drive | MISC | drive.google.com | Exploit, Third Party Advisory |
| DropboxCredentialDump.mp4 - Google Drive | MISC | drive.google.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.