« Volver al listado

CVE-2014-0805

Estado: ModificadaMedia (5.8)—

Directory traversal vulnerability in the NeoFiler application 5.4.3 and earlier, NeoFiler Free application 5.4.3 and earlier, and NeoFiler Lite application 2.4.2 and earlier for Android allows attackers to overwrite or create arbitrary files via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0805",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-01-12T18:34:56.547",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN85716574/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2014-000004",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.skyarts.com/products/android/neofiler/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.skyarts.android.neofiler",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.skyarts.android.neofilerfree",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.skyarts.android.neofilerlite",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN85716574/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2014-000004",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.skyarts.com/products/android/neofiler/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.skyarts.android.neofiler",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.skyarts.android.neofilerfree",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.skyarts.android.neofilerlite",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Directory traversal vulnerability in the NeoFiler application 5.4.3 and earlier, NeoFiler Free application 5.4.3 and earlier, and NeoFiler Lite application 2.4.2 and earlier for Android allows attackers to overwrite or create arbitrary files via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de recorrido de directorios en las aplicaciones para Android NeoFilter 5.4.3 y anteriores, NeoFiler Free 5.4.3 y anteriores, y NeoFiler Lite 2.4.2 y anteriores permite a atacantes remotos sobreescribir o crear archivos de forma arbitraria, a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:03:39.477",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:skyarts:neofiler:*:-:-:*:lite:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "387FE478-6084-4D2B-9706-753EDE3834EA",
              "versionEndIncluding": "2.4.2"
            },
            {
              "criteria": "cpe:2.3:a:skyarts:neofiler:*:-:-:*:-:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C778A6A-05A3-47F4-8D0E-C34A1D5D8725",
              "versionEndIncluding": "5.4.3"
            },
            {
              "criteria": "cpe:2.3:a:skyarts:neofiler:*:-:-:*:free:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3C1CC75-743F-485D-B8CA-315ED863F622",
              "versionEndIncluding": "5.4.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}