Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-09-01 CVE-2012-3337 Path Traversal vulnerability in IBM Infosphere Guardium 8.0/8.01/8.2
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
5.3
2020-09-01 CVE-2020-7669 Path Traversal vulnerability in U-Root
This affects all versions of package github.com/u-root/u-root/pkg/tarutil.
network
low complexity
u-root CWE-22
7.5
2020-09-01 CVE-2020-7666 Path Traversal vulnerability in U-Root
This affects all versions of package github.com/u-root/u-root/pkg/cpio.
network
low complexity
u-root CWE-22
7.5
2020-09-01 CVE-2020-7665 Path Traversal vulnerability in U-Root
This affects all versions of package github.com/u-root/u-root/pkg/uzip.
network
low complexity
u-root CWE-22
7.5
2020-08-31 CVE-2020-25032 Path Traversal vulnerability in multiple products
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9.
network
low complexity
flask-cors-project debian opensuse CWE-22
7.5
2020-08-30 CVE-2020-14352 Path Traversal vulnerability in multiple products
A flaw was found in librepo in versions before 1.12.1.
network
low complexity
redhat opensuse fedoraproject CWE-22
8.0
2020-08-26 CVE-2020-12456 Path Traversal vulnerability in Mitel Mivoice Connect
A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages.
network
low complexity
mitel CWE-22
8.8
2020-08-26 CVE-2020-3490 Path Traversal vulnerability in Cisco Vision Dynamic Signage Director 6.2.0
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct directory traversal attacks and obtain read access to sensitive files on an affected system.
network
low complexity
cisco CWE-22
4.9
2020-08-26 CVE-2020-3440 Path Traversal vulnerability in Cisco Webex Meetings
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system.
network
low complexity
cisco CWE-22
6.5
2020-08-25 CVE-2020-16245 Path Traversal vulnerability in Advantech Iview 5.6/5.7
Advantech iView, Versions 5.7 and prior.
network
low complexity
advantech CWE-22
critical
9.8