Arc represents a narrowly scoped vendor with a focused product footprint, where the observed disclosures center on the Arc product itself. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arc over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9275MEDIUM ARC 5.21q allows directory traversal via a full pathname in an archive file. | Jan 7, 2019 | 5.3 | 16 | NO | NO |
arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945. | Oct 13, 2005 | 2.1 | 11 | NO | NO |
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) ma | Sep 16, 2005 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arc.
Media articles that mention a CVE ID that affects a product developed by Arc — matched by CVE ID, not by vendor name.