CVE-2014-3317
published 2014-07-14CVE-2014-3317: Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows…
PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.56%
83.4th percentile
Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| linux | linux_kernel | >= 5.6.0 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.13.0 < 6.18.3 | 6.18.3 |
| linux | linux_kernel | >= 6.2.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.12.64 | 6.12.64 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
f2fs: fix to avoid updating compression context during writeback
osv·2026-01-13
CVE-2025-68772 f2fs: fix to avoid updating compression context during writeback
f2fs: fix to avoid updating compression context during writeback
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid updating compression context during writeback
Bai, Shuangpeng reported a bug as below:
Oops: divide error: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 11441 Comm: syz.0.46 Not tainted 6.17.0 #1 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
RIP: 0010:f2fs_all_cluster_page_ready+0x106/0x550 fs/f2fs/compress.c:857
Call Trace:
f2fs_write_cache_pages fs/f2fs/data.c:3078 [inline]
__f2fs_write_data_pages fs/f2fs/data.c:3290 [inline]
f2fs_write_data_pages+0x1c19/0x3600 fs/f2fs/data.c:3317
do_writepages+0x38e/0x640 mm/page-writeback.c:2634
filemap_fdatawrite_wbc mm/filemap.c:386 [inline]
__filemap_
GHSA
GHSA-vgm7-45xx-wjr7: Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10
ghsa_unreviewed·2022-05-17
CVE-2014-3317 [MEDIUM] CWE-22 GHSA-vgm7-45xx-wjr7: Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10
Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.
Cisco
Cisco Unified Communications Manager DNA Path Traversal Vulnerability
vendor_cisco·2014-07-10·CVSS 5.5
CVE-2014-3317 [MEDIUM] CWE-22 Cisco Unified Communications Manager DNA Path Traversal Vulnerability
Cisco Unified Communications Manager DNA Path Traversal Vulnerability
A vulnerability in the Multiple Analyzer of the Cisco Unified Communications Manager Dialed Number Analyzer (DNA) could allow an
authenticated, remote attacker to delete files from arbitrary locations on the filesystem.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting crafted URL
requests to a vulnerable device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate to an affected device. This access requirement decreases the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; ho
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59727http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3317http://tools.cisco.com/security/center/viewAlert.x?alertId=34898http://www.securityfocus.com/bid/68481http://www.securitytracker.com/id/1030554https://exchange.xforce.ibmcloud.com/vulnerabilities/94435http://secunia.com/advisories/59727http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3317http://tools.cisco.com/security/center/viewAlert.x?alertId=34898http://www.securityfocus.com/bid/68481http://www.securitytracker.com/id/1030554https://exchange.xforce.ibmcloud.com/vulnerabilities/94435
2014-07-14
Published