Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Alsa MEDIUM 5.5
CVE-2009-0035

alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/als…

Fix: 1.0.20+
Fix from $1,600 2019-11-09
Debian Linux HIGH 7.5
CVE-2013-1809

Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo…

Fix: 3.4.0+
Fix from $1,950 2019-11-07
Lintian MEDIUM 6.3
CVE-2013-1429

Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

Fix: 2.5.10.5+
Fix from $1,600 2019-11-07
Anti Virus MEDIUM 5.5
CVE-2019-18645

The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to pri…

No fix yet
Fix from $1,600 2019-10-31
Autokey MEDIUM 6.5
CVE-2010-0398

The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.

Fix: 0.61.3+
Fix from $1,600 2019-10-30
Rpcbind HIGH 7.1
CVE-2010-2064

rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.

Mitigation only
Fix from $1,950 2019-10-29
Debian Linux HIGH 8.2
CVE-2011-1408

ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

Fix: 3.20110608+
Fix from $1,950 2019-10-29
Hadoop HIGH 7.5
CVE-2012-2945

Hadoop 1.0.3 contains a symlink vulnerability.

No fix yet
Fix from $1,950 2019-10-29
Libpod MEDIUM 5.5
CVE-2019-18466

An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the…

Fix: 1.6.0+
Fix from $1,600 2019-10-28
Deep Security HIGH 7.1
CVE-2019-15627

Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability…

No fix yet
Fix from $1,950 2019-10-17
Windows 10 HIGH 7.8
CVE-2019-1339

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manag…

Patch available
Fix from $1,950 2019-10-10
Windows 10 1607 HIGH 7.8
CVE-2019-1315 KEV

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manag…

Patch available
Fix from $1,950 2019-10-10
Windows 10 HIGH 7.3
CVE-2019-1317

A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

Patch available
Fix from $1,950 2019-10-10
iOS MEDIUM 6.8
CVE-2019-12672

A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to…

Mitigation only
Fix from $1,600 2019-09-25
Windows 10 HIGH 7.8
CVE-2019-1267

An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable …

Patch available
Fix from $1,950 2019-09-11
Windows 10 MEDIUM 5.5
CVE-2019-1270

An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Mic…

Patch available
Fix from $1,600 2019-09-11
Windows 10 HIGH 7.8
CVE-2019-1280EPSS 19%

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who …

Patch available
Fix from $1,950 2019-09-11
Windows 10 1703 HIGH 7.8
CVE-2019-1253 KEVEPSS 12%

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an…

Patch available
Fix from $1,950 2019-09-11
Free Security Suite HIGH 7.8
CVE-2019-11396

An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuratio…

Fix: after 2.0.6.13175
Fix from $1,950 2019-08-29
Tar HIGH 7.5
CVE-2018-20990

An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.

Fix: 0.4.16+
Fix from $1,950 2019-08-26
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1632

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1633

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1634

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1630

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Informix Dynamic Server MEDIUM 6.7
CVE-2018-1631

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu…

Mitigation only
Fix from $1,600 2019-08-20
Windows 10 HIGH 7.5
CVE-2019-1188

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who…

Patch available
Fix from $1,950 2019-08-14
Gpu Driver HIGH 7.8
CVE-2019-5683

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the user mode video driver trace logger component. When an attacker has …

Mitigation only
Fix from $1,950 2019-08-06
Libpod HIGH 7.2
CVE-2019-10152

A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who h…

Fix: 1.4.0+
Fix from $1,950 2019-07-30
Snagit HIGH 7.8
CVE-2019-13382

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorde…

No fix yet
Fix from $1,950 2019-07-26
Wide HIGH 7.5
CVE-2019-13915

b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and ru…

Fix: 1.6.0+
Fix from $1,950 2019-07-18