Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Debian Linux CRITICAL 9.8
CVE-2018-1000544

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …

Fix: after 1.2.1
Fix from $2,300 2018-06-26
Passenger CRITICAL 9.8
CVE-2018-12026

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to rep…

Fix: 5.3.2+
Fix from $2,300 2018-06-17
Firefox MEDIUM 5.3
CVE-2018-5107

The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing pr…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-12015EPSS 7%

In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary…

Fix: 10.14.4+
Fix from $1,950 2018-06-07
Debian Linux HIGH 7.8
CVE-2018-10380

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

Fix: 5.12.6+
Fix from $1,950 2018-05-08
Cylanceprotect HIGH 7.8
CVE-2018-10722

In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify access to the %PROGRAMFILES%…

Fix: 1470+
Fix from $1,950 2018-05-04
Fedora HIGH 7.1
CVE-2013-0159

The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial …

Patch available
Fix from $1,950 2018-05-01
Debian Linux HIGH 8.8
CVE-2016-9602

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to…

Fix: 2.9+
Fix from $1,950 2018-04-26
Mac Os X MEDIUM 5.5
CVE-2018-4112

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to o…

Fix: 10.13.4+
Fix from $1,600 2018-04-03
Thermald MEDIUM 5.5
CVE-2014-2312

The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.

Fix: 1.8+
Fix from $1,600 2018-03-26
Bitbucket CRITICAL 9.9
CVE-2018-5225

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (t…

Fix: 5.4.8 / 5.5.8+
Fix from $2,300 2018-03-22
Spring Boot MEDIUM 5.9
CVE-2018-1196

Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script includ…

Fix: after 1.5.9
Fix from $1,600 2018-03-19
Kubernetes CRITICAL 9.6
CVE-2017-1002101EPSS 12%

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volum…

Fix: 1.7.14 / 1.8.9+
Fix from $2,300 2018-03-13
Rubygems HIGH 7.5
CVE-2018-1000073

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,950 2018-03-13
Debian Linux HIGH 7.5
CVE-2017-2619EPSS 11%

Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file s…

Fix: 4.4.12 / 4.5.7+
Fix from $1,950 2018-03-12
Open Buildservice HIGH 7.8
CVE-2015-0796

In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l…

Fix: 2.4.8 / 2.5.7+
Fix from $1,950 2018-03-02
Open Build Service HIGH 7.5
CVE-2017-5188

The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director…

Fix: after 2.7.3
Fix from $1,950 2018-03-01
Opentmpfiles MEDIUM 5.5
CVE-2017-18188

OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by…

Fix: after 0.1.3
Fix from $1,600 2018-02-14
Ubuntu Linux HIGH 7.8
CVE-2018-6954

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of …

Fix: after 237
Fix from $1,950 2018-02-13
Fedora HIGH 7.8
CVE-2014-3219

fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.…

Fix: 2.1.1+
Fix from $1,950 2018-02-09
Debian Linux HIGH 7.8
CVE-2017-18078

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl…

Fix: 237+
Fix from $1,950 2018-01-29
Keycloak Httpd Client Install MEDIUM 5.5
CVE-2017-15111

keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic li…

Fix: 0.8+
Fix from $1,600 2018-01-20
Vladtheenterprising MEDIUM 5.5
CVE-2014-4996

lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.…

Mitigation only
Fix from $1,600 2018-01-10
Openshift HIGH 7.8
CVE-2013-4364

(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u…

Mitigation only
Fix from $1,950 2018-01-08
Fedora MEDIUM 5.5
CVE-2014-1859

(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local …

Fix: after 1.8.0
Fix from $1,600 2018-01-08
Clipboard MEDIUM 5.5
CVE-2014-5509

clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.

Patch available
Fix from $1,600 2018-01-08
Syncthing HIGH 7.5
CVE-2017-1000420

Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite

Fix: after 0.14.33
Fix from $1,950 2018-01-02
Fedora MEDIUM 5.5
CVE-2014-4978

The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1)…

Patch available
Fix from $1,600 2017-12-29
Postgresql Common HIGH 7.8
CVE-2016-1255

The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befo…

Patch available
Fix from $1,950 2017-12-05
Arq HIGH 7.4
CVE-2017-15357

The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the up…

Fix: 5.9.7+
Fix from $1,950 2017-12-01