Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Checkmk MEDIUM 6.7
CVE-2022-31258

In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

Fix: 1.6.0+
Fix from $1,600 2022-05-20
Password Manager HIGH 7.8
CVE-2022-30523

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could …

Fix: 5.0.0.1270+
Fix from $1,950 2022-05-16
Endpoint Security HIGH 7.8
CVE-2022-23742

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. …

Mitigation only
Fix from $1,950 2022-05-12
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Qts HIGH 8.1
CVE-2021-44052

An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero,…

Fix: 4.3.3.1945 / 4.3.4.1976+
Fix from $1,950 2022-05-05
Android MEDIUM 6.7
CVE-2022-20085

In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with Sys…

Mitigation only
Fix from $1,600 2022-05-03
Ios Xe HIGH 7.2
CVE-2022-20720

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,950 2022-04-15
Agent HIGH 7.8
CVE-2022-1256

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through runn…

Fix: 5.7.6+
Fix from $1,950 2022-04-14
Horizon HIGH 7.8
CVE-2022-22962

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location d…

Fix: 2203+
Fix from $1,950 2022-04-11
Android MEDIUM 6.7
CVE-2022-20068

In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,600 2022-04-11
Antivirus For Mac HIGH 7.3
CVE-2022-27883

A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can…

Fix: after 11.5
Fix from $1,950 2022-04-09
Hadoop CRITICAL 9.8
CVE-2022-26612

In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR …

Fix: 3.2.3+
Fix from $2,300 2022-04-07
Beego HIGH 7.8
CVE-2021-27116

An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.

Fix: after 2.0.2
Fix from $1,950 2022-04-05
Beego HIGH 7.8
CVE-2021-27117

An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks locally.

Fix: after 2.0.2
Fix from $1,950 2022-04-05
Chrome HIGH 8.8
CVE-2022-0799

Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege e…

Fix: 99.0.4844.51+
Fix from $1,950 2022-04-05
Swhkd HIGH 7.1
CVE-2022-27816

SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.

Patch available
Fix from $1,950 2022-03-30
Swhkd HIGH 7.8
CVE-2022-27815

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.

Patch available
Fix from $1,950 2022-03-30
Fedora CRITICAL 9.8
CVE-2022-22995

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combin…

Fix: 5.19.117+
Fix from $2,300 2022-03-25
Docker Desktop HIGH 7.1
CVE-2022-26659

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink i…

Fix: 4.6.0+
Fix from $1,950 2022-03-25
Ipados HIGH 7.5
CVE-2022-22585

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS …

Fix: 8.4 / 11.6.3+
Fix from $1,950 2022-03-18
Android MEDIUM 6.7
CVE-2022-20050

In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,600 2022-03-10
Rog Live Service HIGH 7.7
CVE-2022-22262

ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since t…

Fix: 1.3.3.0+
Fix from $1,950 2022-03-01
Antivirus HIGH 7.8
CVE-2022-24671

A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a fil…

Fix: after 11.0.2150
Fix from $1,950 2022-02-24
Apex One HIGH 7.8
CVE-2022-24679

A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free…

Patch available
Fix from $1,950 2022-02-24
Apex One HIGH 7.8
CVE-2022-24680

A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free…

Patch available
Fix from $1,950 2022-02-24
Snapd HIGH 8.8
CVE-2021-44730

snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to …

Fix: after 2.54.2
Fix from $1,950 2022-02-17
Pipeline\ MEDIUM 6.5
CVE-2022-25176

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configur…

Fix: after 2648.va9433432b33c
Fix from $1,600 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25177

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline l…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,600 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25179

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the conf…

Fix: after 706.vd43c65dec013
Fix from $1,600 2022-02-15
Globalprotect HIGH 7.8
CVE-2022-0017

An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that en…

Fix: 5.1.10 / 5.2.5+
Fix from $1,950 2022-02-10