Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Cargo HIGH 8.1
CVE-2022-36113

Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on…

Fix: 0.65.0+
Fix from $1,950 2022-09-14
Cortex Xdr Agent MEDIUM 5.5
CVE-2022-0029

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the …

Fix: 5.0.12 / 7.5.101+
Fix from $1,600 2022-09-14
Scadapro Client HIGH 7.8
CVE-2022-2897

Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..

Mitigation only
Fix from $1,950 2022-08-31
Scadapro Client MEDIUM 5.5
CVE-2022-2898

Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service conditio…

Mitigation only
Fix from $1,600 2022-08-31
Enterprise Linux MEDIUM 6.7
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to …

Fix: 4.18+
Fix from $1,600 2022-08-26
Enterprise Linux MEDIUM 6.4
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response …

Fix: 4.18.0+
Fix from $1,600 2022-08-25
Fedora MEDIUM 6.7
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged…

Fix: 4.18.0+
Fix from $1,600 2022-08-25
Routeros CRITICAL 9.8
CVE-2022-34960

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations …

No fix yet
Fix from $2,300 2022-08-25
Fedora HIGH 7.8
CVE-2021-23177

An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacke…

Patch available
Fix from $1,950 2022-08-23
Fedora HIGH 7.8
CVE-2021-31566

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file ou…

Patch available
Fix from $1,950 2022-08-23
Apex One HIGH 7.8
CVE-2022-36336

A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker …

Mitigation only
Fix from $1,950 2022-07-30
Velociraptor MEDIUM 5.5
CVE-2022-35631

On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have th…

Fix: 0.6.5-2+
Fix from $1,600 2022-07-29
Tumbleweed HIGH 7.8
CVE-2022-31250

A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to …

Fix: 6.4.2-1.1+
Fix from $1,950 2022-07-20
Anydesk HIGH 7.1
CVE-2022-32450

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad…

No fix yet
Fix from $1,950 2022-07-18
Android MEDIUM 6.7
CVE-2022-21770

In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System exe…

Mitigation only
Fix from $1,600 2022-07-06
Warp HIGH 7.8
CVE-2022-2145

Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the W…

Fix: 2022.5.309.0+
Fix from $1,950 2022-06-28
Safenet Authentication Client MEDIUM 6.7
CVE-2021-42056

Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attack…

Fix: after 10.7.7
Fix from $1,600 2022-06-24
Antivirus HIGH 7.8
CVE-2022-34008

Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS…

No fix yet
Fix from $1,950 2022-06-21
Argo Events HIGH 7.5
CVE-2022-25856

The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read()…

Fix: 1.7.1+
Fix from $1,950 2022-06-17
Yandex Browser HIGH 7.8
CVE-2021-25261

Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code wit…

Fix: 22.5.0.862+
Fix from $1,950 2022-06-15
Yandex Browser HIGH 7.8
CVE-2022-28225

Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code wit…

Fix: 22.3.3.684+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31216

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31217

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31218

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31219

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Deno HIGH 8.4
CVE-2021-41641

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be use…

Fix: after 1.14.0
Fix from $1,950 2022-06-12
Maximum Security 2022 HIGH 7.1
CVE-2022-30687

Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the prod…

Mitigation only
Fix from $1,950 2022-05-27
Mac Os X HIGH 7.8
CVE-2022-26704

A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey …

Fix: 10.15.7 / 11.6.8+
Fix from $1,950 2022-05-26
Go Getter HIGH 8.6
CVE-2022-30321

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i…

Fix: after 1.5.11
Fix from $1,950 2022-05-25
Total Security HIGH 7.0
CVE-2022-31466

Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escal…

Fix: 12.1.1.27+
Fix from $1,950 2022-05-23