Vulnerabilities (CVE)

Filtered by CWE-22
Angry Yack Logo
Total 8266 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8209 1 Citrix 1 Xenmobile Server 2024-11-21 5.0 MEDIUM 7.5 HIGH
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
CVE-2020-8161 3 Canonical, Debian, Rack Project 3 Ubuntu Linux, Debian Linux, Rack 2024-11-21 5.0 MEDIUM 8.6 HIGH
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
CVE-2020-8159 2 Debian, Rubyonrails 2 Debian Linux, Actionpack Page-caching 2024-11-21 7.5 HIGH 9.8 CRITICAL
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
CVE-2020-8144 2 Microsoft, Ui 2 Windows, Unifi Video 2024-11-21 5.2 MEDIUM 8.4 HIGH
The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware update information. If the version field contains ..\ character sequences, the destination file path to save the firmware can be manipulated to be outside the intended destination directory tree. Fixed ...

Show More

CVE-2020-8131 1 Yarnpkg 1 Yarn 2024-11-21 5.1 MEDIUM 7.5 HIGH
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
CVE-2020-8009 1 Motu 21 112d, 1248, 16a and 18 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
CVE-2020-7966 1 Gitlab 1 Gitlab 2024-11-21 5.0 MEDIUM 7.5 HIGH
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
CVE-2020-7882 2 Hancom, Microsoft 2 Anysign4pc, Windows 2024-11-21 6.4 MEDIUM 7.5 HIGH
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
CVE-2020-7861 2 Anysupport, Microsoft 2 Anysupport, Windows 2024-11-21 7.5 HIGH 8.4 HIGH
AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution.
CVE-2020-7858 2 Cdnetworks, Microsoft 2 Aquanplayer, Windows 2024-11-21 5.0 MEDIUM 6.8 MEDIUM
There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulnerability can cause information leakage.
CVE-2020-7790 1 Spatie 1 Browsershot 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
CVE-2020-7763 1 Jsreport 1 Phantom-html-to-pdf 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects the package phantom-html-to-pdf before 0.6.1.
CVE-2020-7762 1 Jsreport 1 Jsreport-chrome-pdf 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
This affects the package jsreport-chrome-pdf before 1.10.0.
CVE-2020-7758 1 Browserless 1 Chrome 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.
CVE-2020-7757 1 Droppy Project 1 Droppy 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.
CVE-2020-7687 1 Fast-http Project 1 Fast-http 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
CVE-2020-7686 1 Rollup-plugin-dev-server Project 1 Rollup-plugin-dev-server 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
CVE-2020-7684 1 Rollup-plugin-serve Project 1 Rollup-plugin-serve 2024-11-21 7.5 HIGH 7.5 HIGH
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
CVE-2020-7683 1 Rollup-plugin-server Project 1 Rollup-plugin-server 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
CVE-2020-7682 1 Marked-tree Project 1 Marked-tree 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
CVE-2020-7681 1 Indo-mars 1 Marscode 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
CVE-2020-7669 1 U-root 1 U-root 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction.
CVE-2020-7668 1 Compression And Archive Extensions Tz Project 1 Compression And Archive Extensions Tz Project 2024-11-21 5.0 MEDIUM 7.5 HIGH
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
CVE-2020-7667 1 Sas 1 Go Rpm Utils 2024-11-21 5.0 MEDIUM 7.5 HIGH
In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all affected versions which were re-released.
CVE-2020-7666 1 U-root 1 U-root 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.
CVE-2020-7665 1 U-root 1 U-root 2024-11-21 5.0 MEDIUM 7.5 HIGH
This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.
CVE-2020-7664 1 Compression And Archive Extensions Project 1 Compression And Archive Extensions Zip Project 2024-11-21 5.0 MEDIUM 7.5 HIGH
In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
CVE-2020-7652 1 Synk 1 Broker 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
CVE-2020-7651 1 Synk 1 Broker 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
CVE-2020-7650 1 Synk 1 Broker 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
CVE-2020-7649 1 Snyk 1 Broker 2024-11-21 N/A 4.9 MEDIUM
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
CVE-2020-7648 1 Synk 1 Broker 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`
CVE-2020-7647 1 Jooby 1 Jooby 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors.
CVE-2020-7535 1 Schneider-electric 42 140cpu65150, 140cpu65150 Firmware, 140cpu65160 and 39 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of information when sending a specially crafted request to the controller over HTTP.
CVE-2020-7529 1 Schneider-electric 1 Scadapack 7x Remote Connect 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.
CVE-2020-7522 1 Schneider-electric 1 Apc Easy Ups Online Software 2024-11-21 7.5 HIGH 9.8 CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.
CVE-2020-7521 1 Schneider-electric 1 Apc Easy Ups Online Software 2024-11-21 7.5 HIGH 9.8 CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories.
CVE-2020-7497 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2024-11-21 7.5 HIGH 9.8 CRITICAL
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.
CVE-2020-7495 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
CVE-2020-7494 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2024-11-21 6.8 MEDIUM 7.8 HIGH
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.