CVE-2015-3999
Summary
| CVE | CVE-2015-3999 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-20 18:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Piriform | Ccleaner | 3.26.1888 | All | All | All |
| Application | Piriform | Ccleaner | 3.27.1900 | All | All | All |
| Application | Piriform | Ccleaner | 3.28.1913 | All | All | All |
| Application | Piriform | Ccleaner | 4.00.4064 | All | All | All |
| Application | Piriform | Ccleaner | 4.01.4093 | All | All | All |
| Application | Piriform | Ccleaner | 4.02.4115 | All | All | All |
| Application | Piriform | Ccleaner | 4.03.4151 | All | All | All |
| Application | Piriform | Ccleaner | 4.04.4197 | All | All | All |
| Application | Piriform | Ccleaner | 4.05.4250 | All | All | All |
| Application | Piriform | Ccleaner | 4.06.4324 | All | All | All |
| Application | Piriform | Ccleaner | 4.07.4369 | All | All | All |
| Application | Piriform | Ccleaner | 4.08.4428 | All | All | All |
| Application | Piriform | Ccleaner | 4.09.4471 | All | All | All |
| Application | Piriform | Ccleaner | 4.10.4570 | All | All | All |
| Application | Piriform | Ccleaner | 4.11.4619 | All | All | All |
| Application | Piriform | Ccleaner | 4.12.4657 | All | All | All |
| Application | Piriform | Ccleaner | 4.13.4693 | All | All | All |
| Application | Piriform | Ccleaner | 4.14.4707 | All | All | All |
| Application | Piriform | Ccleaner | 4.15.4725 | All | All | All |
| Application | Piriform | Ccleaner | 4.16.4763 | All | All | All |
| Application | Piriform | Ccleaner | 4.17.4808 | All | All | All |
| Application | Piriform | Ccleaner | 4.18.4844 | All | All | All |
| Application | Piriform | Ccleaner | 4.19.4867 | All | All | All |
| Application | Piriform | Ccleaner | 5.00.5050 | All | All | All |
| Application | Piriform | Ccleaner | 5.01.5075 | All | All | All |
| Application | Piriform | Ccleaner | 5.02.5101 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: KL-001-2015-002 : Piriform CCleaner Wiped Filename Recovery | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Piriform CCleaner CVE-2015-3999 Arbitrary File Overwrite Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.