Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Debian Linux HIGH 8.1
CVE-2021-41072

squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst…

Patch available
Fix from $1,950 2021-09-14
Maximum Security 2019 HIGH 7.8
CVE-2021-36744

Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the syste…

Patch available
Fix from $1,950 2021-09-06
Debian Linux HIGH 8.6
CVE-2021-37712

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution …

Fix: 1.0.1.1+
Fix from $1,950 2021-08-31
Arborist HIGH 7.8
CVE-2021-39135

`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, ai…

Fix: 1.0.1.1 / 2.8.2+
Fix from $1,950 2021-08-31
Debian Linux HIGH 8.6
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v…

Fix: 1.0.1.1 / 4.4.16+
Fix from $1,950 2021-08-31
Edge Chromium MEDIUM 6.0
CVE-2021-36928

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 92.0.902.55+
Fix from $1,600 2021-08-26
Iphone Os MEDIUM 5.5
CVE-2021-30968

A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS …

Fix: 8.3 / 10.15.7+
Fix from $1,600 2021-08-24
Ipados MEDIUM 5.5
CVE-2021-30855

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Securit…

Fix: 8.0 / 10.15.7+
Fix from $1,600 2021-08-24
Bblfshd CRITICAL 9.1
CVE-2021-32825

bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 there is a "z…

Fix: 2021-08-11+
Fix from $2,300 2021-08-16
Windows 10 HIGH 7.8
CVE-2021-26425

Windows Event Tracing Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Windows 10 HIGH 7.0
CVE-2021-26426

Windows User Account Profile Picture Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Foxit Reader CRITICAL 9.1
CVE-2021-38570

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a sym…

Fix: 10.1.4+
Fix from $2,300 2021-08-11
Tar HIGH 7.5
CVE-2021-38511

An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary director…

Fix: 0.4.36+
Fix from $1,950 2021-08-10
Tar HIGH 8.1
CVE-2021-32803EPSS 8%

The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insuf…

Fix: 1.0.1.1 / 3.2.3+
Fix from $1,950 2021-08-03
Replaysorcery HIGH 7.8
CVE-2021-36983

replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay…

Mitigation only
Fix from $1,950 2021-07-30
Archive Tar HIGH 7.1
CVE-2021-32610EPSS 73%

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Fix: 1.4.14+
Fix from $1,950 2021-07-30
Linux Enterprise Server HIGH 7.1
CVE-2021-32000

A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Serve…

Patch available
Fix from $1,950 2021-07-28
Gpu Display Driver HIGH 7.1
CVE-2021-1091

NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overw…

Fix: 427.48 / 453.10+
Fix from $1,950 2021-07-22
Gpu Display Driver HIGH 7.1
CVE-2021-1092

NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file syst…

Fix: 427.48 / 453.10+
Fix from $1,950 2021-07-22
Forticlient HIGH 7.8
CVE-2021-26089

An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands …

Fix: after 6.4.3
Fix from $1,950 2021-07-12
Storage Manager MEDIUM 6.5
CVE-2021-32508

Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by inject…

Fix: 3.3.3+
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32509

Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injectin…

Fix: 3.3.3+
Fix from $1,600 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32518

A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbitrary files. The referred vul…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Ubuntu Linux MEDIUM 5.5
CVE-2021-32552

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32553

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32554

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package a…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32555

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04…

Mitigation only
Fix from $1,600 2021-06-12
Apport HIGH 7.1
CVE-2021-32557

It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

Fix: 2.14.1-0ubuntu3.29 / 2.20.1-0ubuntu2.30+
Fix from $1,950 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32548

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 pack…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32549

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 pac…

Mitigation only
Fix from $1,600 2021-06-12