Arc
Products
3- 12 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45489 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2024 | Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the… | ||
| CVE-2024-52928 | Cri | 0.62 | 9.6 | 0.00 | Jun 26, 2025 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website. | ||
| CVE-2012-5872 | Cri | 0.57 | 9.8 | 0.01 | Apr 26, 2023 | ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause. | ||
| CVE-2023-5936 | Hig | 0.51 | 7.8 | 0.00 | May 15, 2024 | On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges. | ||
| CVE-2025-14812 | Hig | 0.49 | 7.5 | 0.00 | Dec 19, 2025 | ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk. | ||
| CVE-2026-94183 | Hig | 0.48 | 7.4 | 0.00 | Sep 23, 2026 | Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a… | ||
| CVE-2026-94181 | Hig | 0.48 | 7.4 | 0.00 | Sep 23, 2026 | An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a element that triggers requestFullscreen without displaying the fullscreen notification. | ||
| CVE-2026-18534 | Hig | 0.48 | 7.4 | 0.00 | Aug 18, 2026 | ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk. | ||
| CVE-2026-2378 | Hig | 0.48 | 7.4 | 0.00 | Mar 20, 2026 | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | ||
| CVE-2025-14809 | Hig | 0.48 | 7.4 | 0.00 | Dec 19, 2025 | ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | ||
| CVE-2015-9275 | Med | 0.35 | 5.3 | 0.02 | Jan 7, 2019 | ARC 5.21q allows directory traversal via a full pathname in an archive file. | ||
| CVE-2012-5873 | Med | 0.27 | 5.3 | 0.00 | Apr 26, 2023 | ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action. | ||
| CVE-2005-2992 | 0.00 | — | 0.00 | Oct 13, 2005 | arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945. | |||
| CVE-2005-2945 | 0.00 | — | 0.00 | Sep 16, 2005 | arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c). |
- risk 0.64cvss 9.8epss 0.01
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the…
- risk 0.62cvss 9.6epss 0.00
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
- risk 0.57cvss 9.8epss 0.01
ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.
- risk 0.51cvss 7.8epss 0.00
On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.
- risk 0.49cvss 7.5epss 0.00
ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.
- risk 0.48cvss 7.4epss 0.00
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a…
- risk 0.48cvss 7.4epss 0.00
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a element that triggers requestFullscreen without displaying the fullscreen notification.
- risk 0.48cvss 7.4epss 0.00
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
- risk 0.48cvss 7.4epss 0.00
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- risk 0.48cvss 7.4epss 0.00
ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- risk 0.35cvss 5.3epss 0.02
ARC 5.21q allows directory traversal via a full pathname in an archive file.
- risk 0.27cvss 5.3epss 0.00
ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action.
- CVE-2005-2992Oct 13, 2005risk 0.00cvss —epss 0.00
arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.
- CVE-2005-2945Sep 16, 2005risk 0.00cvss —epss 0.00
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).