Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Geforce Experience HIGH 7.8
CVE-2022-42292

NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic …

Fix: 3.27.0.112+
Fix from $1,950 2023-02-12
Wings HIGH 8.2
CVE-2023-25168

Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vul…

Fix: 1.7.4+
Fix from $1,950 2023-02-09
Wings HIGH 8.8
CVE-2023-25152

Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory str…

Fix: 1.7.3+
Fix from $1,950 2023-02-08
Geforce Experience MEDIUM 5.5
CVE-2022-42291

NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently…

Fix: 3.27.0.112+
Fix from $1,600 2023-02-07
Uptimed HIGH 7.8
CVE-2020-36657

uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within…

Fix: 0.4.6+
Fix from $1,950 2023-01-26
Roomos HIGH 7.1
CVE-2023-20008

A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on …

Mitigation only
Fix from $1,950 2023-01-20
Fedora MEDIUM 6.5
CVE-2022-3592

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path.…

Fix: 4.17.2+
Fix from $1,600 2023-01-12
Windows 10 HIGH 7.1
CVE-2023-21760

Windows Print Spooler Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2023-01-10
Windows 10 1607 HIGH 7.8
CVE-2023-21678

Windows Print Spooler Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2023-01-10
Windows Malicious Software Removal Tool MEDIUM 6.3
CVE-2023-21725

Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability

Fix: 5.109+
Fix from $1,600 2023-01-10
Windows 10 1607 HIGH 7.0
CVE-2023-21542

Windows Installer Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2023-01-10
Ziparchive HIGH 8.1
CVE-2022-36943

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArc…

Fix: after 2.5.3
Fix from $1,950 2023-01-03
Binwalk MEDIUM 6.5
CVE-2021-4287

A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/b…

Fix: 2.3.3+
Fix from $1,600 2022-12-27
Apex One HIGH 7.8
CVE-2022-45798

A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a loc…

Mitigation only
Fix from $1,950 2022-12-24
Firefox HIGH 8.8
CVE-2022-45412

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string con…

Fix: 102.5 / 107.0+
Fix from $1,950 2022-12-22
Securedrop HIGH 7.8
CVE-2022-4563

A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of …

Fix: 2.5.1+
Fix from $1,950 2022-12-16
Fedora MEDIUM 5.3
CVE-2022-4122

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclos…

Patch available
Fix from $1,600 2022-12-08
Open Vm Tools MEDIUM 6.7
CVE-2009-1142

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wr…

Mitigation only
Fix from $1,600 2022-11-23
Open Vm Tools HIGH 7.0
CVE-2009-1143

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink atta…

Patch available
Fix from $1,950 2022-11-23
Cyber Protect Home Office HIGH 7.8
CVE-2022-44747

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor…

Fix: 40107+
Fix from $1,950 2022-11-07
macOS HIGH 7.8
CVE-2022-32905

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may…

Fix: 13.0+
Fix from $1,950 2022-11-01
Fedora HIGH 7.8
CVE-2022-41973

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local use…

Fix: 0.9.2+
Fix from $1,950 2022-10-29
Factory HIGH 7.8
CVE-2022-31256

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory…

Fix: 8.17.1-1.1+
Fix from $1,950 2022-10-26
Git MEDIUM 5.5
CVE-2022-39253

Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2…

Fix: 2.30.6 / 2.31.5+
Fix from $1,600 2022-10-19
Warpinator HIGH 7.5
CVE-2022-42725

Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.

Fix: after 1.2.14
Fix from $1,950 2022-10-10
Deep Security Agent HIGH 7.8
CVE-2022-40710

A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to es…

Mitigation only
Fix from $1,950 2022-09-28
Armoury Crate Service MEDIUM 5.9
CVE-2022-38699

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general us…

Fix: 5.2.10.0+
Fix from $1,600 2022-09-28
Apex One HIGH 7.3
CVE-2022-40143

A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local a…

Patch available
Fix from $1,950 2022-09-19
Security HIGH 7.8
CVE-2022-34893

Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a mountpoint which c…

Fix: after 17.7.1179
Fix from $1,950 2022-09-19
Tauri MEDIUM 5.8
CVE-2022-39215

Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it …

Fix: 1.0.6+
Fix from $1,600 2022-09-15