Vulnerabilities > Radicale > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-02-03 | CVE-2016-1505 | Pathname Traversal and Equivalence Errors vulnerability in Radicale 1.0/1.0.1 The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore. | 10.0 |
2016-02-03 | CVE-2015-8747 | Improper Input Validation vulnerability in Radicale 1.0/1.0.1 The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name. | 10.0 |