Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Debian Linux MEDIUM 5.5
CVE-2017-16611

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, w…

Fix: 1.5.4 / 2.0.3+
Fix from $1,600 2017-12-01
Rpm HIGH 7.8
CVE-2017-7501

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to writ…

Fix: 4.13.0.3+
Fix from $1,950 2017-11-22
PostgreSQL MEDIUM 6.7
CVE-2017-12172

PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a …

Mitigation only
Fix from $1,600 2017-11-22
PostgreSQL MEDIUM 5.5
CVE-2017-8806

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 f…

Mitigation only
Fix from $1,600 2017-11-13
Circle With Disney Firmware HIGH 8.8
CVE-2017-2916

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network …

No fix yet
Fix from $1,950 2017-11-07
Ubuntu Linux HIGH 7.8
CVE-2015-7529

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive fi…

Fix: after 3.8
Fix from $1,950 2017-11-06
Foo2zjs MEDIUM 5.5
CVE-2011-2684

foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged …

Mitigation only
Fix from $1,600 2017-10-23
Tivoli Storage Manager MEDIUM 5.5
CVE-2017-1301

IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporar…

Patch available
Fix from $1,600 2017-10-05
Unified Communications Manager MEDIUM 6.1
CVE-2017-12258

A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame …

Mitigation only
Fix from $1,600 2017-10-05
Debian Linux HIGH 7.5
CVE-2017-1000115

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

Fix: 4.3+
Fix from $1,950 2017-10-05
Instack Undercloud MEDIUM 6.4
CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5…

Mitigation only
Fix from $1,600 2017-09-21
Fedora HIGH 7.5
CVE-2015-5705

Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted fi…

Fix: after 2.15.6
Fix from $1,950 2017-09-06
Php Fpm MEDIUM 5.5
CVE-2015-3211

php-fpm allows local users to write to or create arbitrary files via a symlink attack.

Mitigation only
Fix from $1,600 2017-08-25
Texlive MEDIUM 6.1
CVE-2015-5700

mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.

Patch available
Fix from $1,600 2017-08-25
Texlive MEDIUM 6.1
CVE-2015-5701

mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE:…

Patch available
Fix from $1,600 2017-08-25
Trove MEDIUM 5.5
CVE-2015-3156

The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/…

Fix: after 2014.2.4
Fix from $1,600 2017-08-11
Enterprise Linux Desktop MEDIUM 5.5
CVE-2015-3149

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

Mitigation only
Fix from $1,600 2017-07-25
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-3315

Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sy…

Patch available
Fix from $1,950 2017-06-26
Debian Linux MEDIUM 6.7
CVE-2017-9525

In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to…

Fix: after 3.0pl1-128.
Fix from $1,600 2017-06-09
Pulp HIGH 7.1
CVE-2016-3108

The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.

Fix: after 2.8.2-1
Fix from $1,950 2017-06-08
Lynis HIGH 7.8
CVE-2017-8108

Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary…

Fix: 2.5.0+
Fix from $1,950 2017-06-08
Ansible HIGH 7.8
CVE-2015-6240

The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.

Fix: after 1.9.1
Fix from $1,950 2017-06-07
Fglrx Driver HIGH 7.8
CVE-2015-7723

AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.

No fix yet
Fix from $1,950 2017-06-07
Fglrx Driver HIGH 7.8
CVE-2015-7724

AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix fo…

Fix: after 15.7
Fix from $1,950 2017-06-07
Iptables Parse Module MEDIUM 5.5
CVE-2015-8326

The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.

Patch available
Fix from $1,600 2017-06-07
Iphone Os HIGH 7.8
CVE-2017-6981

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" c…

Fix: after 10.12.4
Fix from $1,950 2017-05-22
Perltidy MEDIUM 5.5
CVE-2016-10374

perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain outpu…

Fix: after 2016-03-02
Fix from $1,600 2017-05-17
Proftpd MEDIUM 5.5
CVE-2017-7418

ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSy…

Fix: after 1.3.5
Fix from $1,600 2017-04-04
Iphone Os MEDIUM 5.5
CVE-2017-2390

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Debian Linux HIGH 7.8
CVE-2016-9774

The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 1…

Mitigation only
Fix from $1,950 2017-03-23