Vulnerabilities > Haystacksoftware

DATE CVE VULNERABILITY TITLE RISK
2022-09-09 CVE-2022-36617 Insufficiently Protected Credentials vulnerability in Haystacksoftware ARQ Backup 7.19.5.0
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption.
network
low complexity
haystacksoftware CWE-522
4.9
2018-01-31 CVE-2017-16945 Incorrect Permission Assignment for Critical Resource vulnerability in Haystacksoftware ARQ
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.
local
low complexity
haystacksoftware CWE-732
7.8
2018-01-31 CVE-2017-16928 Incorrect Permission Assignment for Critical Resource vulnerability in Haystacksoftware ARQ
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.
local
low complexity
haystacksoftware CWE-732
7.8