VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 17 of 25
  • CVE-2020-4075MedJul 7, 2020
    risk 0.37cvss 6.8epss 0.01

    In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` on all new-window events where the `url`…

  • CVE-2026-35440MedMay 12, 2026
    risk 0.36cvss 5.5epss 0.00

    Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2026-32185MedMay 12, 2026
    risk 0.36cvss 5.5epss 0.00

    Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

  • CVE-2025-13225MedNov 19, 2025
    risk 0.36cvss 5.6epss 0.00

    Tanium addressed an arbitrary file deletion vulnerability in TanOS.

  • CVE-2025-30103MedJul 30, 2025
    risk 0.36cvss 5.5epss 0.00

    Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

  • CVE-2023-20039MedNov 15, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could exploit this vulnerability by accessing…

  • CVE-2024-23282MedJun 10, 2024
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A maliciously crafted email may be able to initiate FaceTime calls without user authorization.

  • CVE-2023-41717MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions.

  • CVE-2023-29820MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and…

  • CVE-2022-41710MedNov 3, 2022
    risk 0.36cvss 5.5epss 0.00

    Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough)…

  • CVE-2022-31475MedJul 21, 2022
    risk 0.36cvss 5.5epss 0.01

    Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

  • CVE-2022-29302MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.

  • CVE-2021-43772MedDec 3, 2021
    risk 0.36cvss 5.5epss 0.00

    Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.

  • CVE-2021-42744MedNov 19, 2021
    risk 0.36cvss 5.5epss 0.00

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2020-27368MedJan 14, 2021
    risk 0.36cvss 5.5epss 0.00

    Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.

  • CVE-2019-0381MedOct 8, 2019
    risk 0.36cvss 5.5epss 0.00

    A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

  • CVE-2017-2621MedJul 27, 2018
    risk 0.36cvss 5.5epss 0.00

    An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

  • CVE-2017-7079MedOct 23, 2017
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.

  • CVE-2017-11829MedOct 13, 2017
    risk 0.36cvss 5.5epss 0.04

    Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.

  • CVE-2015-1350MedMay 2, 2016
    risk 0.36cvss 5.5epss 0.00

    The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a…