Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2014-03-31 CVE-2013-6768 Path Traversal vulnerability in Koushik Dutta Superuser 1.0.2.1
Untrusted search path vulnerability in the CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier allows attackers to trigger the launch of a Trojan horse app_process program via a crafted PATH environment variable for a /system/xbin/su process.
network
low complexity
koushik-dutta google CWE-22
5.0
2014-03-25 CVE-2013-1604 Path Traversal vulnerability in Maygion IP Camera Firmware
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a ..
network
low complexity
maygion CWE-22
5.0
2014-03-24 CVE-2014-2588 Path Traversal vulnerability in Mcafee Asset Manager 6.6
Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a ..
network
low complexity
mcafee CWE-22
4.0
2014-03-20 CVE-2014-1970 Path Traversal vulnerability in Estrongs ES File Explorer
Directory traversal vulnerability in the ES File Explorer File Manager application before 3.0.4 for Android allows remote attackers to overwrite or create arbitrary files via unspecified vectors.
5.8
2014-03-19 CVE-2014-1507 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.
network
oracle mozilla CWE-22
critical
9.3
2014-03-19 CVE-2014-1506 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
network
low complexity
mozilla google oracle CWE-22
6.4
2014-03-18 CVE-2014-2536 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.
network
intel mcafee CWE-22
4.3
2014-03-18 CVE-2014-2535 Path Traversal vulnerability in Mcafee web Gateway 7.2.0.9/7.3.2.4/7.4.0
Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web filtering port.
network
low complexity
mcafee CWE-22
4.0
2014-03-18 CVE-2013-2641 Path Traversal vulnerability in Sophos web Appliance and web Appliance Firmware
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
network
low complexity
sophos CWE-22
5.0
2014-03-18 CVE-2013-2619 Path Traversal vulnerability in Aspen 0.8
Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a ..
network
low complexity
aspen CWE-22
5.0