CWE-35Variant1 in KEV

Path Traversal: '.../...//'

Incomplete in the CWE catalog · 172 CVEs mapped

172
CVEs mapped
1
In KEV
7.4
Median CVSS
What it is

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Recent examples
none
CVE-2026-20513

In Audio HAL, there is a possible information disclosure due to improper input validation

In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.

no explanation yet
epss
7.1cvss
CVE-2026-59909

CVE-2026-59909 - HIGH Severity Vulnerability

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

HIGHno explanation yet
0%
epss
3.3cvss
CVE-2026-56089

CVE-2026-56089 - LOW Severity Vulnerability

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-35
Abstraction
Variant
Structure
Simple
Status
Incomplete