Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Linux Enterprise Server HIGH 7.8
CVE-2019-18897

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; …

Mitigation only
Fix from $1,950 2020-03-02
Leap MEDIUM 5.5
CVE-2019-18901

A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE …

Mitigation only
Fix from $1,600 2020-03-02
Nagios HIGH 7.0
CVE-2019-3698

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Ser…

Fix: 3.0.6 / 3.5.1+
Fix from $1,950 2020-02-28
X11 Common HIGH 7.8
CVE-2012-1093

The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during pac…

Fix: 1+
Fix from $1,950 2020-02-21
User Experience Program HIGH 7.8
CVE-2020-8950

The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted…

Fix: after 1.0.0.1
Fix from $1,950 2020-02-12
Windows 10 HIGH 7.1
CVE-2020-0730

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile…

Patch available
Fix from $1,950 2020-02-11
Windows 10 1507 HIGH 7.8
CVE-2020-0683 KEVEPSS 8%

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of…

Patch available
Fix from $1,950 2020-02-11
Ubuntu Linux HIGH 7.8
CVE-2019-11481

Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic …

No fix yet
Fix from $1,950 2020-02-08
MariaDB HIGH 7.8
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are perfor…

Fix: after 10.4.11
Fix from $1,950 2020-02-04
Kubernetes MEDIUM 5.7
CVE-2019-11251

The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provid…

Fix: 1.13.11 / 1.14.7+
Fix from $1,600 2020-02-03
Total Security 2020 MEDIUM 5.5
CVE-2020-8095

A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial…

Fix: 24.9+
Fix from $1,600 2020-01-30
Opensc MEDIUM 6.1
CVE-2013-1866

OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability

Fix: 0.13.0+
Fix from $1,600 2020-01-30
Tokend MEDIUM 6.1
CVE-2013-1867

Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability

Fix: after 03-2013
Fix from $1,600 2020-01-30
Git Extras MEDIUM 5.5
CVE-2012-6114

The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/…

Mitigation only
Fix from $1,600 2020-01-28
Privoxy HIGH 7.8
CVE-2019-3699

UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate fr…

Fix: 3.0.28-lp151.1.1 / 3.0.28-2.1+
Fix from $1,950 2020-01-24
Gnump3d HIGH 7.8
CVE-2019-3697

UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user g…

Fix: after 3.0
Fix from $1,950 2020-01-24
Munin HIGH 7.8
CVE-2019-3694

A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from us…

Fix: after 2.0.49-4.2
Fix from $1,950 2020-01-24
Mailman HIGH 7.8
CVE-2019-3693

A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1…

Fix: 2.1.15-9.6.15.1 / 2.1.17-3.11.1+
Fix from $1,950 2020-01-24
Inn HIGH 7.8
CVE-2019-3692

The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via sym…

Fix: after 2.6.2-2.2
Fix from $1,950 2020-01-24
Munge HIGH 7.8
CVE-2019-3691

A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attack…

Fix: 0.5.13-4.3.1 / 0.5.13-6.1+
Fix from $1,950 2020-01-23
Trousers HIGH 7.8
CVE-2019-18898

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local a…

Fix: 0.3.14-6.3.1 / 0.3.14-7.1+
Fix from $1,950 2020-01-23
Debian Linux HIGH 8.1
CVE-2020-7040

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege …

Fix: after 3.5
Fix from $1,950 2020-01-21
Squid Analysis Report Generator HIGH 7.0
CVE-2019-18932

log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tm…

Fix: after 2.3.11
Fix from $1,950 2020-01-21
Windows 10 1709 HIGH 7.8
CVE-2020-0638 KEV

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker wo…

Patch available
Fix from $1,950 2020-01-14
Windows 10 MEDIUM 5.5
CVE-2020-0616

A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

Patch available
Fix from $1,600 2020-01-14
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-1869

The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on…

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool MEDIUM 6.5
CVE-2015-3147

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to w…

Patch available
Fix from $1,600 2020-01-14
K7 Ultimate Security HIGH 7.8
CVE-2019-16896

In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, al…

No fix yet
Fix from $1,950 2019-12-27
Antivirus HIGH 7.5
CVE-2019-19695

A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symb…

Fix: after 9.0.1379
Fix from $1,950 2019-12-24
Endpoint Security Clients HIGH 7.5
CVE-2019-8463

A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file t…

Patch available
Fix from $1,950 2019-12-23