VulnerabilityModified
CVE-2003-1439
Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.
MEDIUM 4.3EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- silc/secure internet live conferencing
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/309775Exploit
- http://www.securityfocus.com/archive/1/309941/30/26090/threaded
- http://www.securityfocus.com/bid/6743
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11244
- http://www.securityfocus.com/archive/1/309775Exploit
- http://www.securityfocus.com/archive/1/309941/30/26090/threaded
- http://www.securityfocus.com/bid/6743
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11244
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.