Vulnerability Details CVE-2019-12171
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.8%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.3
Products affected by CVE-2019-12171
-
cpe:2.3:a:dropbox:dropbox:71.4.108.0