CVE-2015-3999 describes a vulnerability in Piriform CCleaner versions 3.26.0.1988 through 5.02.5101, where the software writes filenames to disk during file overwriting operations. This allows local attackers to recover sensitive information by examining unallocated disk space. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access and low attack complexity are required to achieve a partial confidentiality impact. There is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and minimal community discussion or media coverage, suggesting a low current threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.26.1888CPE matchmatch criteria | cpe:2.3:a:piriform:ccleaner:3.26.1888:*:*:*:*:*:*:* | ||
3.27.1900CPE matchmatch criteria | cpe:2.3:a:piriform:ccleaner:3.27.1900:*:*:*:*:*:*:* | ||
3.28.1913CPE matchmatch criteria | cpe:2.3:a:piriform:ccleaner:3.28.1913:*:*:*:*:*:*:* | ||
4.00.4064CPE matchmatch criteria | cpe:2.3:a:piriform:ccleaner:4.00.4064:*:*:*:*:*:*:* | ||
4.01.4093CPE matchmatch criteria | cpe:2.3:a:piriform:ccleaner:4.01.4093:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.