Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Code42 HIGH 8.8
CVE-2021-43269

In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) fil…

Fix: 8.8.0+
Fix from $1,950 2022-01-20
Code42 HIGH 7.2
CVE-2020-12736

Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a loca…

Fix: after 7.0.4
Fix from $1,950 2020-07-07
Code42 HIGH 7.3
CVE-2019-16860

Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine …

Fix: after 7.0.2
Fix from $1,950 2019-11-19
Code42 HIGH 7.3
CVE-2019-16861

Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could …

Fix: after 7.0.2
Fix from $1,950 2019-11-19
Code42 CRITICAL 9.8
CVE-2019-15131

In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploa…

Fix: after 6.8.8
Fix from $2,300 2019-09-17
Code42 For Enterprise MEDIUM 5.5
CVE-2019-11551

In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through…

Fix: after 6.9.1
Fix from $1,600 2019-08-21
Code42 HIGH 8.8
CVE-2019-11553

In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can i…

Fix: after 6.8.4
Fix from $1,950 2019-07-19
Code42 For Enterprise HIGH 7.0
CVE-2019-11552

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A p…

Fix: 6.7.5 / 6.8.8+
Fix from $1,950 2019-07-19
Code42 HIGH 7.8
CVE-2018-20131

The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log d…

Fix: 6.8.4+
Fix from $1,950 2019-01-03
Crashplan CRITICAL 9.8
CVE-2017-9830EPSS 6%

Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it cr…

Mitigation only
Fix from $2,300 2017-06-27