Vulnerabilities > Files or Directories Accessible to External Parties

DATE CVE VULNERABILITY TITLE RISK
2019-06-03 CVE-2019-12375 Files or Directories Accessible to External Parties vulnerability in Ivanti Landesk Management Suite 10.0.1.168
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.
low complexity
ivanti CWE-552
4.1
2019-02-11 CVE-2018-9587 Files or Directories Accessible to External Parties vulnerability in Google Android
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a confused deputy scenario.
local
google CWE-552
4.4
2019-01-22 CVE-2017-6922 Files or Directories Accessible to External Parties vulnerability in multiple products
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users.
network
low complexity
drupal debian CWE-552
6.5
2018-09-12 CVE-2018-16946 Files or Directories Accessible to External Parties vulnerability in LG products
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control.
network
low complexity
lg CWE-552
5.0
2018-07-27 CVE-2017-2621 Files or Directories Accessible to External Parties vulnerability in multiple products
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable.
local
low complexity
redhat openstack CWE-552
5.5
2018-07-27 CVE-2017-2622 Files or Directories Accessible to External Parties vulnerability in Redhat Openstack 10
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable.
local
low complexity
redhat CWE-552
5.5
2018-07-19 CVE-2018-10869 Files or Directories Accessible to External Parties vulnerability in Redhat Certification and Enterprise Linux
redhat-certification does not properly restrict files that can be download through the /download page.
network
low complexity
redhat CWE-552
7.5
2018-06-11 CVE-2018-5112 Files or Directories Accessible to External Parties vulnerability in multiple products
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances.
network
low complexity
mozilla canonical CWE-552
5.0
2018-03-23 CVE-2017-1602 Files or Directories Accessible to External Parties vulnerability in IBM products
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL.
network
low complexity
ibm CWE-552
4.0
2018-01-18 CVE-2018-0106 Files or Directories Accessible to External Parties vulnerability in Cisco Elastic Services Controller
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system.
local
low complexity
cisco CWE-552
2.1