Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Sd Wan Firmware MEDIUM 6.5
CVE-2020-3437

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrar…

Fix: 19.2.3+
Fix from $1,600 2020-07-16
Total Protection MEDIUM 6.3
CVE-2020-7282

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not h…

Fix: 16.0.r26+
Fix from $1,600 2020-07-03
Little Snitch HIGH 8.8
CVE-2020-13095

Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by link…

Fix: after 4.5.1
Fix from $1,950 2020-06-30
Advanced Systemcare HIGH 7.1
CVE-2020-14990

IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with a…

No fix yet
Fix from $1,950 2020-06-22
Icinga HIGH 7.8
CVE-2020-14004

An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/…

Fix: after 2.11.3
Fix from $1,950 2020-06-12
Fedora HIGH 8.8
CVE-2020-2026

A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata ru…

Fix: 1.10.5 / 1.11.1+
Fix from $1,950 2020-06-10
Antivirus 2020 HIGH 7.1
CVE-2020-8103

A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined f…

Fix: 1.0.17.178+
Fix from $1,950 2020-06-05
Android CRITICAL 9.1
CVE-2020-13833

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a s…

Mitigation only
Fix from $2,300 2020-06-04
Iox MEDIUM 6.3
CVE-2020-3237

A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to…

Fix: 1.9.0+
Fix from $1,600 2020-06-03
Broker MEDIUM 6.5
CVE-2020-7653

All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's inter…

Fix: 4.80.0+
Fix from $1,600 2020-05-29
Chrome HIGH 7.8
CVE-2020-6477

Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via…

Fix: 83.0.4103.61+
Fix from $1,950 2020-05-21
Runtime MEDIUM 6.5
CVE-2020-2024

An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the …

Fix: 1.11.0+
Fix from $1,600 2020-05-19
Endpoint Protection HIGH 7.8
CVE-2020-5837

Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which ca…

Fix: 14.3+
Fix from $1,950 2020-05-11
It Installer HIGH 8.1
CVE-2020-11443

The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an update…

Fix: 4.6.10+
Fix from $1,950 2020-05-04
Antivirus And Antispyware HIGH 7.8
CVE-2020-11446

ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories…

Fix: after 1560
Fix from $1,950 2020-04-29
Decompress CRITICAL 9.8
CVE-2020-12265

The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because o…

Fix: 4.2.1+
Fix from $2,300 2020-04-26
Antivirus HIGH 7.8
CVE-2020-12254

Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.

Fix: 5.0.2003.1821+
Fix from $1,950 2020-04-26
Ubuntu Linux MEDIUM 5.5
CVE-2020-8831

Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exi…

No fix yet
Fix from $1,600 2020-04-22
Antivirus 2020 MEDIUM 6.2
CVE-2020-8099

A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, …

Fix: 1.0.17+
Fix from $1,600 2020-04-21
Anti Virus For Sophos Central HIGH 8.8
CVE-2020-10947

Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.

Fix: 2.2.6 / 9.9.6+
Fix from $1,950 2020-04-17
Mobile Broadband Driver Package HIGH 7.8
CVE-2020-8948

The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arb…

Fix: 5043+
Fix from $1,950 2020-04-15
Endpoint Security HIGH 7.8
CVE-2020-7250

Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated loca…

Mitigation only
Fix from $1,950 2020-04-15
Gxp1610 Firmware HIGH 8.8
CVE-2020-5738EPSS 5%

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially …

Fix: after 1.0.4.152
Fix from $1,950 2020-04-14
Desktop HIGH 7.8
CVE-2020-1885

Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users to write t…

Fix: 1.44.0.32849+
Fix from $1,950 2020-04-08
Exim HIGH 7.8
CVE-2020-8015

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail…

Fix: 4.93.0.4-3.1+
Fix from $1,950 2020-04-02
Desktop MEDIUM 6.7
CVE-2020-10665

Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privil…

Fix: 2.1.0.9 / 2.2.0.4+
Fix from $1,600 2020-03-18
Windows 10 1507 HIGH 7.8
CVE-2020-0787 KEVEPSS 43%

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka…

Patch available
Fix from $1,950 2020-03-12
Visual Studio 2019 HIGH 7.1
CVE-2020-0789

A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extensi…

Fix: after 16.4
Fix from $1,950 2020-03-12
Windows 10 MEDIUM 5.5
CVE-2020-0779

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of…

Patch available
Fix from $1,600 2020-03-12
Fedora HIGH 7.0
CVE-2020-10174

init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/times…

Fix: 20.03+
Fix from $1,950 2020-03-05