Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-10-29 CVE-2009-3887 Path Traversal vulnerability in Ytnef Project Ytnef
ytnef has directory traversal
network
low complexity
ytnef-project CWE-22
critical
9.8
2019-10-28 CVE-2019-18189 Path Traversal vulnerability in Trendmicro Apex One, Officescan and Worry-Free Business Security
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user.
network
low complexity
trendmicro CWE-22
critical
9.8
2019-10-28 CVE-2019-18187 Path Traversal vulnerability in Trendmicro Officescan 11.0/Xg
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE).
network
low complexity
trendmicro CWE-22
7.5
2019-10-28 CVE-2019-14450 Path Traversal vulnerability in Repetier-Server
A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location.
network
low complexity
repetier-server CWE-22
critical
9.8
2019-10-28 CVE-2019-17224 Path Traversal vulnerability in Compal Ch7465Lg Firmware Ch7465Lgncip6.12.18.252P6Nosh
The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal attack, which can be exploited in order to test for the existence of a file pathname outside of the web root directory.
network
low complexity
compal CWE-22
5.3
2019-10-28 CVE-2005-2349 Path Traversal vulnerability in ZOO Project ZOO 2.1027
Zoo 2.10 has Directory traversal
network
low complexity
zoo-project CWE-22
7.5
2019-10-25 CVE-2019-4400 Path Traversal vulnerability in IBM Cloud Orchestrator
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
4.3
2019-10-25 CVE-2013-4658 Path Traversal vulnerability in Linksys Ea6500 Firmware
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
network
low complexity
linksys CWE-22
critical
9.8
2019-10-25 CVE-2013-4855 Path Traversal vulnerability in Dlink Dir-865L Firmware
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.
low complexity
dlink CWE-22
8.8
2019-10-24 CVE-2019-18393 Path Traversal vulnerability in Igniterealtime Openfire
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.
network
low complexity
igniterealtime CWE-22
5.3