Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Patch MEDIUM 5.9
CVE-2019-13636

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

Fix: after 2.7.6
Fix from $1,600 2019-07-17
Windows 10 1507 HIGH 7.8
CVE-2019-1130 KEV

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…

Patch available
Fix from $1,950 2019-07-15
Windows 10 1703 HIGH 7.8
CVE-2019-1129 KEV

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…

Patch available
Fix from $1,950 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1074

An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic l…

Patch available
Fix from $1,600 2019-07-15
Private Internet Access Vpn Client HIGH 7.1
CVE-2019-12571

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, …

No fix yet
Fix from $1,950 2019-07-11
Private Internet Access Vpn Client HIGH 7.1
CVE-2019-12573

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attack…

No fix yet
Fix from $1,950 2019-07-11
Fedora HIGH 7.0
CVE-2019-13226

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to tem…

Fix: 1.1.3+
Fix from $1,950 2019-07-04
Deepin Clone MEDIUM 5.5
CVE-2019-13227

In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileg…

Fix: 1.1.3+
Fix from $1,600 2019-07-04
Deepin Clone MEDIUM 5.5
CVE-2019-13229

deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follow…

Fix: 1.1.3+
Fix from $1,600 2019-07-04
Fstream HIGH 7.5
CVE-2019-13173

fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the syste…

Fix: 1.0.12+
Fix from $1,950 2019-07-02
Windows 10 MEDIUM 6.3
CVE-2019-1053

An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the …

Patch available
Fix from $1,600 2019-06-12
Windows 10 1607 HIGH 7.8
CVE-2019-1064 KEVEPSS 7%

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successf…

Patch available
Fix from $1,950 2019-06-12
Windows 10 1507 HIGH 7.8
CVE-2019-1069 KEVEPSS 6%

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully …

Patch available
Fix from $1,950 2019-06-12
Windows 10 MEDIUM 6.3
CVE-2019-0986

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfu…

Patch available
Fix from $1,600 2019-06-12
Ubuntu Linux HIGH 7.1
CVE-2019-12749

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less …

Fix: 1.10.28 / 1.12.16+
Fix from $1,950 2019-06-11
Libqb HIGH 7.1
CVE-2019-12779

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /t…

Fix: 1.0.5+
Fix from $1,950 2019-06-07
Pam U2f HIGH 7.5
CVE-2019-12209

Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and…

Patch available
Fix from $1,950 2019-06-04
Osquery HIGH 8.1
CVE-2019-3567

In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali…

Fix: 3.4.0+
Fix from $1,950 2019-06-03
My Cloud Firmware HIGH 8.8
CVE-2019-9949

Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a …

Fix: 2.31.183+
Fix from $1,950 2019-05-23
Converged Security Management Engine Firmware HIGH 7.8
CVE-2019-0086

Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.…

Fix: 3.1.65 / 11.8.65+
Fix from $1,950 2019-05-17
Windows 10 HIGH 7.8
CVE-2019-0936

An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevat…

Patch available
Fix from $1,950 2019-05-16
Harp MEDIUM 5.3
CVE-2019-5438

Path traversal using symlink in npm harp module versions <= 0.29.0.

Fix: after 0.29.0
Fix from $1,600 2019-05-10
Webrick MEDIUM 5.5
CVE-2019-11879

The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web …

Mitigation only
Fix from $1,600 2019-05-10
Nx Os HIGH 7.1
CVE-2019-1836

A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authe…

Mitigation only
Fix from $1,950 2019-05-03
Tar HIGH 7.5
CVE-2018-20834

A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarb…

Fix: 2.2.2 / 4.4.2+
Fix from $1,950 2019-04-30
Endpoint Security HIGH 7.0
CVE-2019-8454

A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another…

Mitigation only
Fix from $1,950 2019-04-29
Connect Secure HIGH 7.7
CVE-2019-11538EPSS 7%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS pro…

No fix yet
Fix from $1,950 2019-04-26
Snapd HIGH 7.5
CVE-2019-11502

snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, tha…

Fix: 2.38+
Fix from $1,950 2019-04-24
Snapd HIGH 7.5
CVE-2019-11503

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the…

Fix: 2.39+
Fix from $1,950 2019-04-24
Endpoint Security HIGH 7.8
CVE-2019-8452

A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 t…

Fix: after 15.4.062
Fix from $1,950 2019-04-22