CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

483 vulnerabilities with CWE-552
CVE-2018-10867 CRITICAL
redhat-certification 7 - Info Disclosure
CVSS 9.1
CVE-2018-10863 HIGH
redhat-certification 7 - Info Disclosure
CVSS 7.5
CVE-2018-9587 HIGH
Android - Local Privilege Escalation
CVSS 7.3
CVE-2018-16946 HIGH
LG Smart Network Camera Firmware 1310250-1508190 - Unauthenticated Sensitive Information Exposure
CVSS 7.5
CVE-2018-10869 HIGH
redhat-certification - Info Disclosure
CVSS 7.5
CVE-2018-5112 HIGH
Firefox < 58 - Privileged Page Access via Extension Development Tools Panel
CVSS 7.5
CVE-2018-1079 HIGH
pacemaker_command_line_interface < 0.9.164 - Authenticated Arbitrary File Write via REST /remote/put_file
CVSS 8.7
CVE-2018-0106 LOW
Cisco Elastic Services Controller - Unauthenticated Sensitive Information Exposure via ConfD Directory Access
CVSS 3.3
CVE-2017-6922 MEDIUM
Drupal Core <8.3.4 & 7.x <7.56 - Auth Bypass
CVSS 6.5
CVE-2017-2621 MEDIUM
OpenStack Orchestration <8.0.0, 6.1.0, 7.0.2 - Info Disclosure
CVSS 5.5
CVE-2017-2622 MEDIUM
OpenStack Workflow - Info Disclosure
CVSS 5.9
CVE-2017-1602 MEDIUM
IBM Rational Collaborative Lifecycle Management 5.0-6.0 - Authenticated Unauthorized Access via Crafted URL
CVSS 4.3
CVE-2017-15104 HIGH
Heketi < 5.0.1 - Unauthorized Sensitive Information Exposure via World-Readable Configuration File
CVSS 7.8
CVE-2017-12079 HIGH
Synology Photo Station <6.8.1-3458, <6.3-2970 - Info Disclosure
CVSS 7.5
CVE-2017-16651 HIGH KEV
Roundcube Webmail <1.1.10, 1.2.x <1.2.7, 1.3.x <1.3.3 - Arbitrary File Access
CVSS 7.8
CVE-2017-7079 MEDIUM
iTunes < 12.7 - Unauthorized iOS Backup Access via Data Sync Component
CVSS 5.5
CVE-2017-11829 MEDIUM
Microsoft Windows 10 - Privilege Escalation
CVSS 5.5
CVE-2017-14942 CRITICAL
Intelbras WRN 150 - Authentication Bypass
CVSS 9.8
CVE-2017-2551 HIGH
Wordpress plugin BackWPup <3.4.2 - Info Disclosure
CVSS 7.5
CVE-2017-10930 CRITICAL
ZXR10 1800-2S <3.00.40 - Privilege Escalation
CVSS 9.8
CVE-2017-6774 MEDIUM
Cisco ASR 5000 - Privilege Escalation
CVSS 5.0
CVE-2017-7737 MEDIUM
Fortinet FortiWeb <5.8.2 - Info Disclosure
CVSS 4.9
CVE-2017-11746 HIGH
Tenshi 0.15 - Arbitrary Process Termination via PID File Manipulation
CVSS 7.5
CVE-2017-1308 MEDIUM
IBM Daeja ViewONE <5.0 - Info Disclosure
CVSS 6.5
CVE-2016-20025 HIGH
ZKTeco ZKAccess Professional 3.5.3 Privilege Escalation via Insecure Permissions
CVSS 8.8
Details
Vulnerabilities 483