Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Antivirus\+ Security 2020 HIGH 7.1
CVE-2019-19693

The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive informatio…

Fix: 16.0.1249+
Fix from $1,950 2019-12-20
Ipados MEDIUM 5.5
CVE-2019-8789

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.…

Fix: 10.15.1 / 13.2+
Fix from $1,600 2019-12-18
Iphone Os MEDIUM 5.5
CVE-2019-8568

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.…

Fix: 5.2.1 / 10.14.5+
Fix from $1,600 2019-12-18
Yarn HIGH 7.8
CVE-2019-10773

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially craft…

Fix: 1.21.1+
Fix from $1,950 2019-12-16
Enterprise Linux MEDIUM 6.5
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…

Fix: 6.13.3+
Fix from $1,600 2019-12-13
Sentinel Ldk License Manager HIGH 7.8
CVE-2019-18232

SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a se…

Fix: 7.101+
Fix from $1,950 2019-12-11
Windows 10 HIGH 7.8
CVE-2019-1483

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an…

Patch available
Fix from $1,950 2019-12-10
Debian Linux MEDIUM 5.5
CVE-2013-4184

Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

Fix: 1.224+
Fix from $1,600 2019-12-10
Command\|configure HIGH 7.1
CVE-2019-18575

Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploi…

Fix: 4.2.1+
Fix from $1,950 2019-12-06
Qts CRITICAL 9.8
CVE-2019-7183

This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to…

Mitigation only
Fix from $2,300 2019-12-05
Command Update MEDIUM 5.5
CVE-2019-3749

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges …

Fix: 3.1+
Fix from $1,600 2019-12-03
Command Update MEDIUM 5.5
CVE-2019-3750

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges …

Fix: 3.1+
Fix from $1,600 2019-12-03
Debian Linux HIGH 7.1
CVE-2011-3632

Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Openvas Scanner HIGH 7.1
CVE-2011-3351

openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated…

Fix: 2011-09-11+
Fix from $1,950 2019-11-25
Eda Agent MEDIUM 5.5
CVE-2019-17445

An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operatio…

Fix: after 10.2.26
Fix from $1,600 2019-11-22
Service Provider HIGH 7.8
CVE-2019-19191

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the sh…

Fix: 3.1.0+
Fix from $1,950 2019-11-21
Rply MEDIUM 5.5
CVE-2014-1938

python-rply before 0.7.4 insecurely creates temporary files.

Fix: 0.7.4+
Fix from $1,600 2019-11-21
Debian Linux MEDIUM 5.5
CVE-2011-2924

foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mod…

Fix: after 4.0.12
Fix from $1,600 2019-11-19
Debian Linux MEDIUM 5.5
CVE-2011-2923

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode w…

Mitigation only
Fix from $1,600 2019-11-19
Iceweasel Firegpg HIGH 7.8
CVE-2008-7273

A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.

Fix: 0.6+
Fix from $1,950 2019-11-18
Debian Linux MEDIUM 5.5
CVE-2010-4817

pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

Fix: 0.3.5+
Fix from $1,600 2019-11-13
Fedora HIGH 8.6
CVE-2019-18837

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to…

Fix: 0.10.5+
Fix from $1,950 2019-11-13
N900 Firmware HIGH 7.5
CVE-2013-4655

Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.

No fix yet
Fix from $1,950 2019-11-13
Windows 10 HIGH 7.8
CVE-2019-1422

An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Ele…

Patch available
Fix from $1,950 2019-11-12
Windows 10 HIGH 7.8
CVE-2019-1423

An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations, aka 'Windows Eleva…

Patch available
Fix from $1,950 2019-11-12
Visual Studio 2017 MEDIUM 6.5
CVE-2019-1425

An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual S…

Patch available
Fix from $1,600 2019-11-12
Windows 10 1709 HIGH 7.8
CVE-2019-1385 KEV

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc…

Patch available
Fix from $1,950 2019-11-12
Debian Linux HIGH 7.8
CVE-2011-3618

atop: symlink attack possible due to insecure tempfile handling

Patch available
Fix from $1,950 2019-11-12
Pacemaker MEDIUM 5.5
CVE-2011-5271

Pacemaker before 1.1.6 configure script creates temporary files insecurely

Fix: 1.1.6+
Fix from $1,600 2019-11-12
Helm CRITICAL 9.8
CVE-2019-18658

In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously desig…

Fix: 2.15.2+
Fix from $2,300 2019-11-12