This page aggregates publicly disclosed CVE and security risk information related to xcfa_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2014-5255 | xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254. | [email protected] | 7.0 | 0.37% | 2019-11-21 | 2026-06-16 |
| CVE-2014-5254 | xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. | [email protected] | 4.7 | 0.34% | 2019-11-21 | 2026-06-16 |