Vulnerability index

Browse CVEs

71 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.9 CVE-2019-3902 A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil… Debian Linux 4.9+ Fix from $1,6002019-04-22 MEDIUM 5.4 CVE-2019-3880 A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this fla… Debian Linux 4.8.11 / 4.9.6+ Fix from $1,6002019-04-09 HIGH 7.5 CVE-2018-19052EPSS 14% An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single dir… Debian Linux 1.4.50+ Fix from $1,9502018-11-07 HIGH 7.5 CVE-2018-13982 Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitiza… Debian Linux 3.1.33+ Fix from $1,9502018-09-18 MEDIUM 5.5 CVE-2018-1000801 okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that ca… Debian Linux after 18.08 Fix from $1,6002018-09-06 HIGH 7.5 CVE-2018-14912EPSS 93% cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg… Debian Linux 1.2.1+ Fix from $1,9502018-08-03 MEDIUM 5.5 CVE-2018-1002200EPSS 13% plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arc… Debian Linux 3.6.0+ Fix from $1,6002018-07-25 HIGH 7.5 CVE-2018-14363 An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache … Debian Linux 20180716+ Fix from $1,9502018-07-17 MEDIUM 5.3 CVE-2018-14355 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name. Debian Linux 1.10.1 / 20180716+ Fix from $1,6002018-07-17 MEDIUM 5.3 CVE-2018-14056 ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories. Debian Linux after 1.7.0 Fix from $1,6002018-07-15 CRITICAL 9.8 CVE-2018-1000550 The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that… Debian Linux 6.2.32+ Fix from $2,3002018-06-26 HIGH 7.5 CVE-2018-0496 Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allo… Debian Linux 3.14+ Fix from $1,9502018-06-12 HIGH 7.8 CVE-2018-11235EPSS 49% In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. Wi… Debian Linux after 2.16.3 Fix from $1,9502018-05-30 HIGH 7.5 CVE-2018-11319 Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potent… Debian Linux after 3.9.0 Fix from $1,9502018-05-20 HIGH 7.5 CVE-2014-10073 The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is und… Debian Linux 1.1.4+ Fix from $1,9502018-04-20 HIGH 8.8 CVE-2018-8741 A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting serve… Debian Linux Patch available Fix from $1,9502018-03-17 HIGH 7.5 CVE-2018-7490EPSS 69% uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal. Debian Linux 2.0.17+ Fix from $1,9502018-02-26 MEDIUM 6.5 CVE-2017-1000472 The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the … Debian Linux 1.8+ Fix from $1,6002018-01-03 CRITICAL 9.8 CVE-2017-1000501 Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthen… Debian Linux after 7.6.0 Fix from $2,3002018-01-03 CRITICAL 9.1 CVE-2017-8805 Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a… Ftpsync after 20171016 Fix from $2,3002017-10-17 HIGH 7.5 CVE-2017-14120 unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] a… Debian Linux Mitigation only Fix from $1,9502017-09-03 HIGH 7.5 CVE-2017-0901EPSS 29% RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th… Debian Linux Patch available Fix from $1,9502017-08-31 HIGH 7.5 CVE-2011-5325EPSS 7% Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current… Debian Linux after 1.21.1 Fix from $1,9502017-08-07 MEDIUM 5.5 CVE-2017-8314 Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles. Debian Linux after 17.1 Fix from $1,6002017-05-23 CRITICAL 9.8 CVE-2017-8283 dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hu… Dpkg Patch available Fix from $2,3002017-04-26 HIGH 7.8 CVE-2017-6306 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilen… Debian Linux after 1.9 Fix from $1,9502017-02-24 MEDIUM 6.0 CVE-2016-7116 Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the … Debian Linux after 2.6.2 Fix from $1,6002016-12-10 MEDIUM 5.3 CVE-2015-5345EPSS 18% The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before con… Debian Linux No fix yet Fix from $1,6002016-02-25 HIGH 7.5 CVE-2013-7448 Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get. Debian Linux Patch available Fix from $1,9502016-02-23 MEDIUM 6.4 CVE-2014-3864 Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a … Dpkg Dev Mitigation only Fix from $1,6002014-05-30