VYPR
Vendor

Arc

Products
2
CVEs
12
Across products
13
Status
Private

Products

2

Recent CVEs

12
  • CVE-2024-45489CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the…

  • CVE-2024-52928CriJun 26, 2025
    risk 0.62cvss 9.6epss 0.00

    Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.

  • CVE-2012-5872CriApr 26, 2023
    risk 0.57cvss 9.8epss 0.01

    ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.

  • CVE-2023-5936HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.

  • CVE-2025-14812HigDec 19, 2025
    risk 0.49cvss 7.5epss 0.00

    ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.

  • CVE-2026-2378HigMar 20, 2026
    risk 0.48cvss 7.4epss 0.00

    ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

  • CVE-2025-14809HigDec 19, 2025
    risk 0.48cvss 7.4epss 0.00

    ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

  • CVE-2026-47735higJun 8, 2026
    risk 0.39cvss epss 0.00

    ### Summary Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family — `read_csv_auto`, `read_csv`, `read_json`, `read_json_auto`, `read_text`,…

  • CVE-2015-9275MedJan 7, 2019
    risk 0.35cvss 5.3epss 0.02

    ARC 5.21q allows directory traversal via a full pathname in an archive file.

  • CVE-2012-5873MedApr 26, 2023
    risk 0.27cvss 5.3epss 0.00

    ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action.

  • CVE-2005-2992Oct 13, 2005
    risk 0.00cvss epss 0.00

    arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.

  • CVE-2005-2945Sep 16, 2005
    risk 0.00cvss epss 0.00

    arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).