CWE-249Variant

DEPRECATED: Often Misused: Path Manipulation

Deprecated in the CWE catalog · 6 CVEs mapped

6
CVEs mapped
6.7
Median CVSS
What it is

This entry has been deprecated because of name

confusion and an accidental combination of multiple

weaknesses. Most of its content has been transferred to

CWE-785.

Recent examples
6.7cvss
CVE-2023-35003

Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via…

Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

MEDIUMno explanation yet
0%
epss
6.7cvss
CVE-2023-32655

Path transversal in some Intel(R) NUC Kits & Mini PCs - NUC8i7HVK & NUC8HNK USB Type C power delivery controller installatio software before version 1.0.10.3…

Path transversal in some Intel(R) NUC Kits & Mini PCs - NUC8i7HVK & NUC8HNK USB Type C power delivery controller installatio software before version 1.0.10.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

MEDIUMno explanation yet
0%
epss
6.7cvss
CVE-2023-32278

Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installation…

Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installation software before version 1.0.1.7 for Intel(R) NUC Software Studio may allow an authenticated user to potentially enable escalation of privilege via local access.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-249
Abstraction
Variant
Structure
Simple
Status
Deprecated