Vulnerability index

Browse CVEs

71 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Debian Linux MEDIUM 5.9
CVE-2019-3902

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil…

Fix: 4.9+
Fix from $1,600 2019-04-22
Debian Linux MEDIUM 5.4
CVE-2019-3880

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this fla…

Fix: 4.8.11 / 4.9.6+
Fix from $1,600 2019-04-09
Debian Linux HIGH 7.5
CVE-2018-19052EPSS 14%

An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single dir…

Fix: 1.4.50+
Fix from $1,950 2018-11-07
Debian Linux HIGH 7.5
CVE-2018-13982

Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitiza…

Fix: 3.1.33+
Fix from $1,950 2018-09-18
Debian Linux MEDIUM 5.5
CVE-2018-1000801

okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that ca…

Fix: after 18.08
Fix from $1,600 2018-09-06
Debian Linux HIGH 7.5
CVE-2018-14912EPSS 93%

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg…

Fix: 1.2.1+
Fix from $1,950 2018-08-03
Debian Linux MEDIUM 5.5
CVE-2018-1002200EPSS 13%

plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arc…

Fix: 3.6.0+
Fix from $1,600 2018-07-25
Debian Linux HIGH 7.5
CVE-2018-14363

An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache …

Fix: 20180716+
Fix from $1,950 2018-07-17
Debian Linux MEDIUM 5.3
CVE-2018-14355

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.

Fix: 1.10.1 / 20180716+
Fix from $1,600 2018-07-17
Debian Linux MEDIUM 5.3
CVE-2018-14056

ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

Fix: after 1.7.0
Fix from $1,600 2018-07-15
Debian Linux CRITICAL 9.8
CVE-2018-1000550

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that…

Fix: 6.2.32+
Fix from $2,300 2018-06-26
Debian Linux HIGH 7.5
CVE-2018-0496

Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allo…

Fix: 3.14+
Fix from $1,950 2018-06-12
Debian Linux HIGH 7.8
CVE-2018-11235EPSS 49%

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. Wi…

Fix: after 2.16.3
Fix from $1,950 2018-05-30
Debian Linux HIGH 7.5
CVE-2018-11319

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potent…

Fix: after 3.9.0
Fix from $1,950 2018-05-20
Debian Linux HIGH 7.5
CVE-2014-10073

The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is und…

Fix: 1.1.4+
Fix from $1,950 2018-04-20
Debian Linux HIGH 8.8
CVE-2018-8741

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting serve…

Patch available
Fix from $1,950 2018-03-17
Debian Linux HIGH 7.5
CVE-2018-7490EPSS 69%

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

Fix: 2.0.17+
Fix from $1,950 2018-02-26
Debian Linux MEDIUM 6.5
CVE-2017-1000472

The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the …

Fix: 1.8+
Fix from $1,600 2018-01-03
Debian Linux CRITICAL 9.8
CVE-2017-1000501

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthen…

Fix: after 7.6.0
Fix from $2,300 2018-01-03
Ftpsync CRITICAL 9.1
CVE-2017-8805

Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a…

Fix: after 20171016
Fix from $2,300 2017-10-17
Debian Linux HIGH 7.5
CVE-2017-14120

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] a…

Mitigation only
Fix from $1,950 2017-09-03
Debian Linux HIGH 7.5
CVE-2017-0901EPSS 29%

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th…

Patch available
Fix from $1,950 2017-08-31
Debian Linux HIGH 7.5
CVE-2011-5325EPSS 7%

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current…

Fix: after 1.21.1
Fix from $1,950 2017-08-07
Debian Linux MEDIUM 5.5
CVE-2017-8314

Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.

Fix: after 17.1
Fix from $1,600 2017-05-23
Dpkg CRITICAL 9.8
CVE-2017-8283

dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hu…

Patch available
Fix from $2,300 2017-04-26
Debian Linux HIGH 7.8
CVE-2017-6306

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilen…

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux MEDIUM 6.0
CVE-2016-7116

Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the …

Fix: after 2.6.2
Fix from $1,600 2016-12-10
Debian Linux MEDIUM 5.3
CVE-2015-5345EPSS 18%

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before con…

No fix yet
Fix from $1,600 2016-02-25
Debian Linux HIGH 7.5
CVE-2013-7448

Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get.

Patch available
Fix from $1,950 2016-02-23
Dpkg Dev MEDIUM 6.4
CVE-2014-3864

Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a …

Mitigation only
Fix from $1,600 2014-05-30