Vulnerability index

Browse CVEs

49 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Tensorflow CRITICAL 9.1
CVE-2021-35958

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. …

Fix: after 2.5.0
Fix from $2,300 2021-06-30
Android HIGH 8.8
CVE-2021-25361

An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of …

Mitigation only
Fix from $1,950 2021-04-09
Secret Manager Provider For Secret Store Csi Driver MEDIUM 6.5
CVE-2020-8567

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who…

Fix: 0.0.6 / 0.0.10+
Fix from $1,600 2021-01-21
Android MEDIUM 5.3
CVE-2020-26603

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows directory traversal for an unprivi…

Mitigation only
Fix from $1,600 2020-10-06
Android MEDIUM 5.5
CVE-2020-15583

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to…

Mitigation only
Fix from $1,600 2020-07-07
Android HIGH 7.8
CVE-2020-0179

In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escala…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.5
CVE-2020-13836

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. …

Mitigation only
Fix from $1,950 2020-06-04
Android HIGH 7.5
CVE-2019-9281

In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction …

Mitigation only
Fix from $1,950 2019-09-27
Rendertron HIGH 7.5
CVE-2017-18354

Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by…

Patch available
Fix from $1,950 2018-12-17
Android HIGH 8.8
CVE-2018-9459

In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal er…

Mitigation only
Fix from $1,950 2018-11-06
Android MEDIUM 6.8
CVE-2018-9445

In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when …

Patch available
Fix from $1,600 2018-11-06
Chrome HIGH 8.1
CVE-2016-1671

Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversa…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Chrome Os HIGH 7.5
CVE-2014-1707

Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors.

Fix: after 33.0.1750.149
Fix from $1,950 2014-03-16
Chrome HIGH 7.5
CVE-2014-1715

Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact …

Fix: 33.0.1750.152 / 33.0.1750.154+
Fix from $1,950 2014-03-16
Chrome HIGH 7.5
CVE-2013-6652

Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to by…

Fix: after 33.0.1750.116
Fix from $1,950 2014-02-24
Chrome HIGH 7.5
CVE-2013-0911

Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to …

Fix: after 25.0.1364.126
Fix from $1,950 2013-03-05
Chrome HIGH 7.5
CVE-2013-0895

Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which mig…

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,950 2013-02-23
Chrome HIGH 7.5
CVE-2013-0831

Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to have an unspecified impact by leveraging access to …

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Kml MEDIUM 5.0
CVE-2007-6212

Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer para…

No fix yet
Fix from $1,600 2007-12-04