CVE-2014-5254: Xcfa Project Xcfa

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.

Affected products

Published 2019-11-21. Last modified 2026-06-17.