Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Ubuntu Linux MEDIUM 5.5
CVE-2021-32550

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32551

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32547

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts pa…

Mitigation only
Fix from $1,600 2021-06-12
Python Postorius HIGH 7.8
CVE-2021-31997

A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from use…

Fix: 1.3.2-lp152.1.2+
Fix from $1,950 2021-06-10
Driver \& Support Assistant HIGH 7.8
CVE-2021-0094

Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escala…

Fix: 20.11.50.9+
Fix from $1,950 2021-06-09
Private Tunnel HIGH 7.8
CVE-2020-15076

Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp.

Fix: after 3.0.1
Fix from $1,950 2021-05-26
True Image 2020 HIGH 7.8
CVE-2020-9452

An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a su…

No fix yet
Fix from $1,950 2021-05-25
Openshift Container Platform HIGH 7.1
CVE-2020-27833

A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c…

Fix: after 4.7
Fix from $1,950 2021-05-14
Total Protection HIGH 7.8
CVE-2021-23872

Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated …

Fix: 16.0.32+
Fix from $1,950 2021-05-12
Endpoint Security For Linux Threat Prevention HIGH 7.0
CVE-2021-23892

By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/F…

Fix: 10.7.5+
Fix from $1,950 2021-05-12
Windows 10 HIGH 7.8
CVE-2021-31187

Windows WalletService Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Exim HIGH 7.8
CVE-2020-28007

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a s…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Guix MEDIUM 5.5
CVE-2021-27851

A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-dae…

Fix: 1.2.0+
Fix from $1,600 2021-04-26
Identity Agent HIGH 8.1
CVE-2021-30356

A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite…

Mitigation only
Fix from $1,950 2021-04-22
Counteract HIGH 7.8
CVE-2021-28098

An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureCo…

Fix: 8.1.4+
Fix from $1,950 2021-04-14
Visual Studio HIGH 7.8
CVE-2021-28321

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

Fix: after 16.9
Fix from $1,950 2021-04-13
Control Panel HIGH 7.8
CVE-2021-30463

VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY va…

Fix: after 0.9.8-24
Fix from $1,950 2021-04-08
Connect HIGH 7.1
CVE-2020-15075

OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.

Fix: after 3.2.6
Fix from $1,950 2021-03-30
Premium Security MEDIUM 6.1
CVE-2021-27241

This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Security 20.8.2429 (Build 20.8.5…

Mitigation only
Fix from $1,600 2021-03-29
Enterprise Linux MEDIUM 6.3
CVE-2021-20197

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When…

Fix: after 2.35
Fix from $1,600 2021-03-26
Data Loss Prevention HIGH 7.8
CVE-2020-7346

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker throug…

Fix: 11.6.100+
Fix from $1,950 2021-03-23
Fedora MEDIUM 5.5
CVE-2021-28650

autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extrac…

Fix: 0.3.1+
Fix from $1,600 2021-03-17
Debian Linux MEDIUM 5.3
CVE-2021-28153

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a…

Fix: 2.66.8+
Fix from $1,600 2021-03-11
Windows 10 HIGH 7.8
CVE-2021-26887

An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirectio…

Patch available
Fix from $1,950 2021-03-11
Windows 10 HIGH 7.8
CVE-2021-26889

Windows Update Stack Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Windows 10 HIGH 7.0
CVE-2021-26862

Windows Installer Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Windows 10 HIGH 7.1
CVE-2021-26866

Windows Update Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Windows 10 HIGH 7.0
CVE-2021-26873

Windows User Profile Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Spss Modeler MEDIUM 5.5
CVE-2020-4717

A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in …

Mitigation only
Fix from $1,600 2021-03-10
My Cloud Os HIGH 7.8
CVE-2021-3310

Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and in…

Fix: 5.10.122+
Fix from $1,950 2021-03-10