Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2019-3902
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil…
Debian Linux
4.9+
MEDIUM 5.4
CVE-2019-3880
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this fla…
Debian Linux
4.8.11 / 4.9.6+
HIGH 7.5
CVE-2018-19052EPSS 14%
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single dir…
Debian Linux
1.4.50+
HIGH 7.5
CVE-2018-13982
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitiza…
Debian Linux
3.1.33+
MEDIUM 5.5
CVE-2018-1000801
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that ca…
Debian Linux
after 18.08
HIGH 7.5
CVE-2018-14912EPSS 93%
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg…
Debian Linux
1.2.1+
MEDIUM 5.5
CVE-2018-1002200EPSS 13%
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arc…
Debian Linux
3.6.0+
HIGH 7.5
CVE-2018-14363
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache …
Debian Linux
20180716+
MEDIUM 5.3
CVE-2018-14355
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
Debian Linux
1.10.1 / 20180716+
MEDIUM 5.3
CVE-2018-14056
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
Debian Linux
after 1.7.0
CRITICAL 9.8
CVE-2018-1000550
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that…
Debian Linux
6.2.32+
HIGH 7.5
CVE-2018-0496
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allo…
Debian Linux
3.14+
HIGH 7.8
CVE-2018-11235EPSS 49%
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. Wi…
Debian Linux
after 2.16.3
HIGH 7.5
CVE-2018-11319
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potent…
Debian Linux
after 3.9.0
HIGH 7.5
CVE-2014-10073
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is und…
Debian Linux
1.1.4+
HIGH 8.8
CVE-2018-8741
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting serve…
Debian Linux
Patch available
HIGH 7.5
CVE-2018-7490EPSS 69%
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
Debian Linux
2.0.17+
MEDIUM 6.5
CVE-2017-1000472
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the …
Debian Linux
1.8+
CRITICAL 9.8
CVE-2017-1000501
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthen…
Debian Linux
after 7.6.0
CRITICAL 9.1
CVE-2017-8805
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a…
Ftpsync
after 20171016
HIGH 7.5
CVE-2017-14120
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] a…
Debian Linux
Mitigation only
HIGH 7.5
CVE-2017-0901EPSS 29%
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th…
Debian Linux
Patch available
HIGH 7.5
CVE-2011-5325EPSS 7%
Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current…
Debian Linux
after 1.21.1
MEDIUM 5.5
CVE-2017-8314
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.
Debian Linux
after 17.1
CRITICAL 9.8
CVE-2017-8283
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hu…
Dpkg
Patch available
HIGH 7.8
CVE-2017-6306
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilen…
Debian Linux
after 1.9
MEDIUM 6.0
CVE-2016-7116
Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the …
Debian Linux
after 2.6.2
MEDIUM 5.3
CVE-2015-5345EPSS 18%
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before con…
Debian Linux
No fix yet
HIGH 7.5
CVE-2013-7448
Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get.
Debian Linux
Patch available
MEDIUM 6.4
CVE-2014-3864
Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a …
Dpkg Dev
Mitigation only