CWE-552
479 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Datasecurity Plus Jun 17, 2026 Oct 9, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the passw...Show more |
1Sap 3Dynamic Tier Sap IqSql AnywhereJun 17, 2026 Oct 8, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of...Show more |
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories. |
In SilverStripe assets 4.0, there is broken access control on files. |
1Intenogroup 1Eg200 Firmware Jun 17, 2026 Sep 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisionin...Show more |
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99). |
1Mcafee 1Data Loss Prevention Endpoint Jun 17, 2026 Jul 24, 2019 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access...Show more |
1Siemens 2Digsi 5 Engineering Software Siprotec 5 Digsi Device DriverJun 17, 2026 Jul 11, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V...Show more |
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the...Show more |
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure....Show more |
1Ivanti 1Landesk Management Suite Jun 17, 2026 Jun 3, 2019 N/A· v4 6.3 MEDIUM· v3 4.1 MEDIUM· v2 Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution. |
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a conf...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Jan 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous...Show more |
4Debian FedoraprojectOpensuse+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 15, 2019 N/A· v4 5.2 MEDIUM· v3 2.7 LOW· v2 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that res...Show more |
1Lg 18Lnb5110 Firmware Lnb5320 FirmwareLnb5320r Firmware+15 moreNov 21, 2024 Sep 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without aut...Show more |
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this fl...Show more |
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive informatio...Show more |
1Redhat 2Certification Enterprise LinuxNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd. |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development...Show more |
2Clusterlabs Redhat2Enterprise Linux Pacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_fil...Show more |