CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical Flightcrew ProjectSigil Ebook3Flightcrew SigilUbuntu LinuxJun 17, 2026 Jul 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. |
2Canonical Flightcrew Project2Flightcrew Ubuntu LinuxJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. |
1Flightcrew Project 1Flightcrew Jun 17, 2026 Jun 28, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This...Show more |