← Back

CVE-2016-1242

nvd nist
Published: Sep 7, 2016Modified: May 6, 2026

JSON object

Loading...
4.4
Vector
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.7 / Impact: 3.6
Source: NVD

Description

file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.

Affected (40)

Products: Tryton: Tryton
1 product
Tryton
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Tryton
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.2.16
Configuration C
7 vulnerable
Vulnerable SoftwareAffected Versions
Tryton
Version 3.8.0
Version 3.8.1
Version 3.8.2
Version 3.8.3
Version 3.8.5
Version 3.8.6
Version 3.8.7
Configuration D
15 vulnerable
Vulnerable SoftwareAffected Versions
Tryton
Version 3.4.0
Version 3.4.10
Version 3.4.11
Version 3.4.12
Version 3.4.13
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.9
Version 3.8.4
Configuration E
13 vulnerable
Vulnerable SoftwareAffected Versions
Tryton
Version 3.2.0
Version 3.6.0
Version 3.6.10
Version 3.6.11
Version 3.6.1
Version 3.6.2
Version 3.6.3
Version 3.6.4
Version 3.6.5
Version 3.6.6
Version 3.6.7
Version 3.6.8
Version 3.6.9

References (6)

Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.