CWE-552
506 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (506)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462. |
2Debian Vmware2Debian Linux Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user cra...Show more |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelMay 6, 2026 May 2, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of servic...Show more |
1Digitaldesign Cms Project 1Digitaldesign Cms Apr 23, 2026 Oct 8, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd. |
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb. |