« Volver al listado

ARC

ARC: vulnerabilidades y CVE

ARC tiene 12 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94181Alta (7.4)0.26%—23 sept 2026
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
CVE-2026-55678Media (6.9)0.66%—28 ago 2026
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but…
CVE-2026-48105Alta (8.3)0.22%—21 ago 2026
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in…
CVE-2026-48050Alta (8.8)0.64%—21 ago 2026
Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and…
CVE-2026-47735Alta (7.1)0.43%—21 ago 2026
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via…
CVE-2024-45489Crítica (9.8)1.2%—20 sept 2024
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a…
CVE-2023-5938Alta (8.9)0.67%—15 may 2024
Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be…
CVE-2023-5937Media (5.2)0.14%—15 may 2024
On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.
CVE-2023-5936Alta (7.3)0.15%—15 may 2024
On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.
CVE-2023-5935Alta (7.3)0.16%—15 may 2024
When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware…
CVE-2005-2992Baja (2.1)0.36%—13 oct 2005
arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.
CVE-2005-2945Baja (2.1)0.36%—16 sept 2005
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System3
  2. T1210 Exploitation of Remote Services2
  3. T1190 Exploit Public-Facing Application1
  4. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de ARC