{"api_version":"1","generated_at":"2026-07-23T04:58:23+00:00","cve":"CVE-2014-2079","urls":{"html":"https://cve.report/CVE-2014-2079","api":"https://cve.report/api/cve/CVE-2014-2079.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2079","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2079"},"summary":{"title":"CVE-2014-2079","description":"X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-07-16 14:29:00","updated_at":"2018-09-15 12:31:00"},"problem_types":["CWE-264"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/65748","name":"65748","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"X File Explorer 'FilePanel::onCmdNewFile' Function Access Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2014/02/24/5","name":"[oss-security] 20140224 Re: xfe: directory masks ignored when creating new files on Samba and NFS","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: xfe: directory masks ignored when creating new files on Samba and NFS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739536","name":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739536","refsource":"CONFIRM","tags":["Mailing List","Patch","Third Party Advisory"],"title":"#739536 - xfe: CVE-2014-2079: directory masks ignored when creating new files on Samba and NFS - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1069066","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1069066","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1069066 – (CVE-2014-2079) CVE-2014-2079 xfe: directory masks ignored when creating new files on Samba and NFS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91519","name":"xfile-explorer-cve20142079-sec-bypass(91519)","refsource":"XF","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2079","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2079","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2079","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2079","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2079","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2079","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2079","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"x_file_explorer_project","cpe5":"x_file_explorer","cpe6":"1.32.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2079","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"x_file_explorer_project","cpe5":"x_file_explorer","cpe6":"1.32.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-2079","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1069066","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1069066"},{"name":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739536","refsource":"CONFIRM","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739536"},{"name":"xfile-explorer-cve20142079-sec-bypass(91519)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91519"},{"name":"[oss-security] 20140224 Re: xfe: directory masks ignored when creating new files on Samba and NFS","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2014/02/24/5"},{"name":"65748","refsource":"BID","url":"http://www.securityfocus.com/bid/65748"}]}},"nvd":{"publishedDate":"2018-07-16 14:29:00","lastModifiedDate":"2018-09-15 12:31:00","problem_types":["CWE-264"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:x_file_explorer_project:x_file_explorer:1.32.5:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2079","Ordinal":"68960","Title":"CVE-2014-2079","CVE":"CVE-2014-2079","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2079","Ordinal":"1","NoteData":"X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.","Type":"Description","Title":null},{"CveYear":"2014","CveId":"2079","Ordinal":"2","NoteData":"2018-07-16","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2079","Ordinal":"3","NoteData":"2018-07-16","Type":"Other","Title":"Modified"}]}}}