CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
474 vulnerabilities with CWE-552
CVE-2017-2621
MEDIUM
OpenStack Orchestration <8.0.0, 6.1.0, 7.0.2 - Info Disclosure
CVSS 5.5
CVE-2017-2622
MEDIUM
OpenStack Workflow - Info Disclosure
CVSS 5.9
CVE-2017-1602
MEDIUM
IBM Rational Collaborative Lifecycle Management 5.0-6.0 - Authenticated Unauthorized Access via Crafted URL
CVSS 4.3
CVE-2017-15104
HIGH
Heketi < 5.0.1 - Unauthorized Sensitive Information Exposure via World-Readable Configuration File
CVSS 7.8
CVE-2017-12079
HIGH
Synology Photo Station <6.8.1-3458, <6.3-2970 - Info Disclosure
CVSS 7.5
CVE-2017-16651
HIGH
KEV
Roundcube Webmail <1.1.10, 1.2.x <1.2.7, 1.3.x <1.3.3 - Arbitrary File Access
CVSS 7.8
CVE-2017-7079
MEDIUM
iTunes < 12.7 - Unauthorized iOS Backup Access via Data Sync Component
CVSS 5.5
CVE-2017-11829
MEDIUM
Microsoft Windows 10 - Privilege Escalation
CVSS 5.5
CVE-2017-14942
CRITICAL
Intelbras WRN 150 - Authentication Bypass
CVSS 9.8
CVE-2017-2551
HIGH
Wordpress plugin BackWPup <3.4.2 - Info Disclosure
CVSS 7.5
CVE-2017-10930
CRITICAL
ZXR10 1800-2S <3.00.40 - Privilege Escalation
CVSS 9.8
CVE-2017-6774
MEDIUM
Cisco ASR 5000 - Privilege Escalation
CVSS 5.0
CVE-2017-7737
MEDIUM
Fortinet FortiWeb <5.8.2 - Info Disclosure
CVSS 4.9
CVE-2017-11746
HIGH
Tenshi 0.15 - Arbitrary Process Termination via PID File Manipulation
CVSS 7.5
CVE-2017-1308
MEDIUM
IBM Daeja ViewONE <5.0 - Info Disclosure
CVSS 6.5
CVE-2016-20025
HIGH
ZKTeco ZKAccess Professional 3.5.3 Privilege Escalation via Insecure Permissions
CVSS 8.8
CVE-2016-10829
MEDIUM
cPanel <55.9999.141 - Info Disclosure
CVSS 6.5
CVE-2016-3715
MEDIUM
KEV
ImageMagick <6.9.3-10, <7.0.1-1 - Remote Code Execution
CVSS 5.5
CVE-2015-4715
MEDIUM
ownCloud Server <6.0.8, <7.0.6, <8.0.4 - Info Disclosure
CVSS 4.9
CVE-2015-5211
CRITICAL
Spring Framework <4.2.1, 3.2.14 - RFD
CVSS 9.6
CVE-2015-1350
MEDIUM
Linux Kernel 3.0-3.19.7 - Local Denial of Service via VFS setattr Capability Stripping
CVSS 5.5
CVE-2009-10005
HIGH
ContentKeeper Web Appliance <125.10 - Path Traversal
CVE-2009-3597
Digitaldesign CMS 0.1 - Info Disclosure
CVE-2005-1835
nextweb (i)site - Unauthenticated Sensitive Information Exposure via Direct Database Request
Details
Vulnerabilities
474