Vulnerability index

Browse CVEs

49 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.1 CVE-2021-35958 TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. … Tensorflow after 2.5.0 Fix from $2,3002021-06-30 HIGH 8.8 CVE-2021-25361 An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of … Android Mitigation only Fix from $1,9502021-04-09 MEDIUM 6.5 CVE-2020-8567 Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who… Secret Manager Provider For Secret Store Csi Driver 0.0.6 / 0.0.10+ Fix from $1,6002021-01-21 MEDIUM 5.3 CVE-2020-26603 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows directory traversal for an unprivi… Android Mitigation only Fix from $1,6002020-10-06 MEDIUM 5.5 CVE-2020-15583 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to… Android Mitigation only Fix from $1,6002020-07-07 HIGH 7.8 CVE-2020-0179 In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escala… Android Patch available Fix from $1,9502020-06-11 HIGH 7.5 CVE-2020-13836 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. … Android Mitigation only Fix from $1,9502020-06-04 HIGH 7.5 CVE-2019-9281 In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction … Android Mitigation only Fix from $1,9502019-09-27 HIGH 7.5 CVE-2017-18354 Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by… Rendertron Patch available Fix from $1,9502018-12-17 HIGH 8.8 CVE-2018-9459 In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal er… Android Mitigation only Fix from $1,9502018-11-06 MEDIUM 6.8 CVE-2018-9445 In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when … Android Patch available Fix from $1,6002018-11-06 HIGH 8.1 CVE-2016-1671 Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversa… Chrome after 50.0.2661.87 Fix from $1,9502016-05-14 HIGH 7.5 CVE-2014-1707 Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors. Chrome Os after 33.0.1750.149 Fix from $1,9502014-03-16 HIGH 7.5 CVE-2014-1715 Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact … Chrome 33.0.1750.152 / 33.0.1750.154+ Fix from $1,9502014-03-16 HIGH 7.5 CVE-2013-6652 Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to by… Chrome after 33.0.1750.116 Fix from $1,9502014-02-24 HIGH 7.5 CVE-2013-0911 Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to … Chrome after 25.0.1364.126 Fix from $1,9502013-03-05 HIGH 7.5 CVE-2013-0895 Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which mig… Chrome 25.0.1364.97 / 25.0.1364.99+ Fix from $1,9502013-02-23 HIGH 7.5 CVE-2013-0831 Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to have an unspecified impact by leveraging access to … Chrome after 24.0.1312.51 Fix from $1,9502013-01-15 MEDIUM 5.0 CVE-2007-6212 Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer para… Kml No fix yet Fix from $1,6002007-12-04