Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Endpoint Security MEDIUM 5.5
CVE-2020-6015

Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage…

Mitigation only
Fix from $1,600 2020-11-05
Chrome HIGH 7.8
CVE-2020-16007

Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a cra…

Fix: 86.0.4240.183+
Fix from $1,950 2020-11-03
Openrc MEDIUM 5.5
CVE-2018-21269

checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlin…

Fix: after 0.42.1
Fix from $1,600 2020-10-27
Opentmpfiles MEDIUM 5.5
CVE-2017-18925

opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

Fix: after 0.3.1
Fix from $1,600 2020-10-26
Ipados HIGH 7.8
CVE-2020-9901

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS …

Fix: 10.15.6 / 13.4.8+
Fix from $1,950 2020-10-22
Ipados HIGH 7.8
CVE-2020-9900

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS …

Fix: 6.2.8 / 10.15.6+
Fix from $1,950 2020-10-22
Windows 10 HIGH 7.8
CVE-2020-16939

<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerabili…

Patch available
Fix from $1,950 2020-10-16
Antivirus HIGH 7.8
CVE-2020-25776

Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical…

Mitigation only
Fix from $1,950 2020-10-02
Officescan HIGH 7.8
CVE-2020-24562

A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which th…

Mitigation only
Fix from $1,950 2020-09-29
Hotspot Shield HIGH 7.8
CVE-2020-17365

Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially e…

Fix: after 10.3.0
Fix from $1,950 2020-09-24
Chrome HIGH 7.8
CVE-2020-6546

Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a cra…

Fix: 84.0.4147.125+
Fix from $1,950 2020-09-21
Safervpn HIGH 8.1
CVE-2020-25744

SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (Do…

Fix: 5.0.3.3+
Fix from $1,950 2020-09-18
Secureline Vpn MEDIUM 5.5
CVE-2020-25289

The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the l…

Fix: 5.6.4982.470+
Fix from $1,600 2020-09-13
Onedrive HIGH 7.1
CVE-2020-16851

<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker wh…

Patch available
Fix from $1,950 2020-09-11
Onedrive HIGH 7.1
CVE-2020-16853

<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker wh…

Patch available
Fix from $1,950 2020-09-11
Endpoint Security HIGH 8.8
CVE-2020-7319

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to acces…

Fix: 10.7.0+
Fix from $1,950 2020-09-09
Mvision Endpoint HIGH 7.8
CVE-2020-7325

Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would …

Fix: 20.9+
Fix from $1,950 2020-09-09
Professional X HIGH 7.8
CVE-2020-24955

SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a maliciou…

Fix: 10.0.1206+
Fix from $1,950 2020-09-01
Apex One HIGH 7.8
CVE-2020-24559

A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attack…

Mitigation only
Fix from $1,950 2020-09-01
Apex One HIGH 7.8
CVE-2020-24556

A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsof…

Mitigation only
Fix from $1,950 2020-09-01
Checkinstall HIGH 7.8
CVE-2020-25031

checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.

No fix yet
Fix from $1,950 2020-08-31
Fedora MEDIUM 6.0
CVE-2020-14367

A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd star…

Fix: 3.5.1+
Fix from $1,600 2020-08-24
Ubuntu Linux HIGH 7.8
CVE-2020-15861

Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.

Fix: after 5.7.3
Fix from $1,950 2020-08-20
Finereader HIGH 7.8
CVE-2019-20383

ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulat…

Fix: 15.0.112.2130+
Fix from $1,950 2020-08-13
Fedora MEDIUM 5.5
CVE-2020-24332

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone…

Fix: after 0.3.14
Fix from $1,600 2020-08-13
Zonealarm Anti Ransomware HIGH 7.4
CVE-2020-6012

ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can…

Fix: 1.0.713+
Fix from $1,950 2020-08-04
Secure Enterprise Client HIGH 7.8
CVE-2020-11474

NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

Fix: after 10.15
Fix from $1,950 2020-07-28
Overwolf HIGH 8.8
CVE-2020-15932

Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.

Fix: 0.149.2.30+
Fix from $1,950 2020-07-24
Creative Cloud Desktop Application CRITICAL 9.8
CVE-2020-9682

Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to a…

Fix: after 5.1
Fix from $2,300 2020-07-17
Creative Cloud Desktop Application CRITICAL 9.8
CVE-2020-9670

Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to p…

Fix: after 5.1
Fix from $2,300 2020-07-17