Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Debian Linux MEDIUM 5.9
CVE-2019-3902

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil…

Fix: 4.9+
Fix from $1,600 2019-04-22
Zonealarm HIGH 7.1
CVE-2019-8455

A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all u…

Fix: after 15.4.062
Fix from $1,950 2019-04-17
Windows 10 1703 HIGH 7.8
CVE-2019-0841 KEVEPSS 41%

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…

Patch available
Fix from $1,950 2019-04-09
Kubernetes MEDIUM 5.5
CVE-2019-1002101EPSS 13%

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside …

Fix: 1.11.9 / 1.12.7+
Fix from $1,600 2019-04-01
Geforce Experience HIGH 7.0
CVE-2019-5674

NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system an…

Fix: 3.18+
Fix from $1,950 2019-03-28
Yast2 Multipath MEDIUM 5.5
CVE-2018-17955

In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection

Fix: 4.1.1+
Fix from $1,600 2019-03-15
Supportutils MEDIUM 5.5
CVE-2018-19637

Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symli…

Fix: 3.1-5.7.1+
Fix from $1,600 2019-03-05
Gpu Driver HIGH 7.8
CVE-2019-5665

NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does…

Patch available
Fix from $1,950 2019-02-27
Lha.sys HIGH 7.0
CVE-2019-8372

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physi…

Fix: 1.1.1811.2101+
Fix from $1,950 2019-02-18
Windows 10 HIGH 7.8
CVE-2019-0572EPSS 25%

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Se…

Patch available
Fix from $1,950 2019-01-08
Windows 10 HIGH 7.8
CVE-2019-0574EPSS 19%

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Se…

Patch available
Fix from $1,950 2019-01-08
Db2 HIGH 7.8
CVE-2018-1780

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root acc…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1781

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploit…

Mitigation only
Fix from $1,950 2018-11-09
Db2 HIGH 7.8
CVE-2018-1834

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to…

Mitigation only
Fix from $1,950 2018-11-09
Debian Linux HIGH 8.8
CVE-2018-14651

It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authentica…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Jekyll HIGH 7.5
CVE-2018-17567

Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include…

Fix: after 3.8.3
Fix from $1,950 2018-09-28
Debian Linux HIGH 8.8
CVE-2018-10928

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gl…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Ubuntu Linux HIGH 7.0
CVE-2018-6557

The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled te…

Mitigation only
Fix from $1,950 2018-08-21
Pyro HIGH 7.5
CVE-2011-2765

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overw…

Fix: 3.15+
Fix from $1,950 2018-08-20
24f2xg Router Firmware MEDIUM 6.5
CVE-2018-15351

Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware vers…

Fix: after 3.5.30.1118
Fix from $1,600 2018-08-17
Rpm HIGH 7.8
CVE-2017-7500

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownersh…

Fix: 4.13.0.2+
Fix from $1,950 2018-08-13
Virtualization HIGH 8.1
CVE-2018-10897EPSS 6%

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil…

Fix: after 1.1.31
Fix from $1,950 2018-08-01
Nagios HIGH 7.8
CVE-2016-8641

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing th…

Patch available
Fix from $1,950 2018-08-01
Enterprise Linux Desktop MEDIUM 6.7
CVE-2017-15097

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could…

Mitigation only
Fix from $1,600 2018-07-27
Satellite MEDIUM 5.5
CVE-2016-9595

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla…

Fix: 3.4.0+
Fix from $1,600 2018-07-27
H2 MEDIUM 6.5
CVE-2018-14335EPSS 13%

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of t…

No fix yet
Fix from $1,600 2018-07-24
Scheme48 MEDIUM 5.5
CVE-2014-4150

The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48l…

Patch available
Fix from $1,600 2018-07-20
Check Mk MEDIUM 5.5
CVE-2014-0243

Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.

Fix: after 1.2.5
Fix from $1,600 2018-07-19
Powermedia Xms HIGH 7.5
CVE-2018-11637

Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary file…

Fix: after 3.5
Fix from $1,950 2018-07-03
Debian Linux HIGH 8.1
CVE-2018-13054

An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) ot…

Fix: after 3.8.6
Fix from $1,950 2018-07-02