{"id":"DEBIAN-CVE-2016-5537","details":"Unspecified vulnerability in the NetBeans component in Oracle Fusion Middleware 8.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the October 2016 CPU. Oracle has not commented on third-party claims that this issue is a directory traversal vulnerability which allows local users with certain permissions to write to arbitrary files and consequently gain privileges via a .. (dot dot) in a archive entry in a ZIP file imported as a project.","modified":"2025-11-19T01:19:08.059116Z","published":"2016-10-25T14:30:13.053Z","upstream":["CVE-2016-5537"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2016-5537"}],"affected":[{"package":{"name":"netbeans","ecosystem":"Debian:11","purl":"pkg:deb/debian/netbeans?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2016-5537.json"}},{"package":{"name":"netbeans","ecosystem":"Debian:12","purl":"pkg:deb/debian/netbeans?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2016-5537.json"}},{"package":{"name":"netbeans","ecosystem":"Debian:13","purl":"pkg:deb/debian/netbeans?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2016-5537.json"}},{"package":{"name":"netbeans","ecosystem":"Debian:14","purl":"pkg:deb/debian/netbeans?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2016-5537.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"}]}