Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2016-08-03 CVE-2016-5639 Path Traversal vulnerability in Crestron Airmedia Am-100 Firmware 1.2.1/1.4.0.12
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a ..
network
low complexity
crestron CWE-22
7.5
2016-08-02 CVE-2016-6232 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
network
low complexity
canonical kde CWE-22
7.5
2016-08-01 CVE-2016-1610 Path Traversal vulnerability in Novell Filr 1.2/2.0
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a ..
network
low complexity
novell CWE-22
7.5
2016-08-01 CVE-2016-1605 Path Traversal vulnerability in Netiq Sentinel 7.4/7.4.1
Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.
network
low complexity
netiq CWE-22
6.5
2016-07-13 CVE-2016-5092 Path Traversal vulnerability in Fortinet Fortiweb
Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature.
network
low complexity
fortinet CWE-22
4.9
2016-07-12 CVE-2016-2205 Path Traversal vulnerability in Symantec Workspace Streaming and Workspace Virtualization
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read unspecified application files via unknown vectors.
low complexity
symantec CWE-22
5.7
2016-07-05 CVE-2016-5098 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
network
low complexity
phpmyadmin opensuse CWE-22
5.3
2016-07-02 CVE-2016-2872 Path Traversal vulnerability in IBM products
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
network
low complexity
ibm CWE-22
5.3
2016-06-30 CVE-2016-5307 Path Traversal vulnerability in Symantec Endpoint Protection Manager 12.1.6
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.
network
low complexity
symantec CWE-22
4.3
2016-06-19 CVE-2016-1191 Path Traversal vulnerability in Cybozu Garoon
Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.
network
low complexity
cybozu CWE-22
5.3