Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Iphone Os MEDIUM 5.5
CVE-2016-7619

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2016-4679

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat…

Fix: 3.1 / 10.0.1+
Fix from $1,600 2017-02-20
Netbsd HIGH 7.8
CVE-2016-6253

mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary fil…

No fix yet
Fix from $1,950 2017-01-20
Nagios HIGH 7.8
CVE-2016-9566

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink att…

Fix: after 4.2.3
Fix from $1,950 2016-12-15
MySQL HIGH 7.0
CVE-2016-6664

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before …

Fix: 5.5.41-37.0 / 5.5.51-38.2+
Fix from $1,950 2016-12-13
Nginx HIGH 7.8
CVE-2016-1247

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.0…

Fix: after 1.10.1
Fix from $1,950 2016-11-29
Studio Express HIGH 7.8
CVE-2016-7490

The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could c…

No fix yet
Fix from $1,950 2016-11-10
Fedora HIGH 7.8
CVE-2016-3096

The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary file…

Fix: after 1.9.6
Fix from $1,950 2016-06-03
Fedora HIGH 8.4
CVE-2015-6566

zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vaca…

Fix: after 7.2.0
Fix from $1,950 2016-01-11
Automatic Bug Reporting Tool MEDIUM 6.9
CVE-2015-5287

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges vi…

Fix: after 2.7.0
Fix from $1,600 2015-12-07
Ubuntu Linux HIGH 7.2
CVE-2015-1338

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symli…

Fix: after 2.18.1
Fix from $1,950 2015-10-01
Ubuntu Linux HIGH 7.2
CVE-2015-1335

lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (…

Fix: after 1.0.7
Fix from $1,950 2015-10-01
Iphone Os MEDIUM 5.0
CVE-2015-5752

Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.

Fix: after 8.4
Fix from $1,600 2015-08-17
Zarafa Collaboration Platform MEDIUM 6.6
CVE-2015-3436

provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary fil…

Fix: after 7.1.12
Fix from $1,600 2015-06-09
Libcontainer HIGH 7.8
CVE-2015-3629

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file …

No fix yet
Fix from $1,950 2015-05-18
Docker HIGH 7.2
CVE-2015-3627

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local us…

Fix: after 1.6.0
Fix from $1,950 2015-05-18
Mac Os X HIGH 7.8
CVE-2015-1130 KEVEPSS 10%

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via un…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Fedora MEDIUM 5.8
CVE-2015-0556

Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.

Fix: after 3.10.22
Fix from $1,600 2015-04-08
Rsync MEDIUM 6.4
CVE-2014-9512EPSS 6%

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

No fix yet
Fix from $1,600 2015-02-12
Iphone Os HIGH 10.0
CVE-2014-4480

Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintende…

Fix: after 8.1.2
Fix from $1,950 2015-01-30
Fedora MEDIUM 5.8
CVE-2015-1038

p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

No fix yet
Fix from $1,600 2015-01-21
Docker HIGH 7.5
CVE-2014-6407

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an im…

Fix: after 1.3.1
Fix from $1,950 2014-12-12
Hadoop MEDIUM 5.0
CVE-2014-3627

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u…

Mitigation only
Fix from $1,600 2014-12-05
Download Manager MEDIUM 5.0
CVE-2014-8585

Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (do…

No fix yet
Fix from $1,600 2014-11-04
Tools MEDIUM 6.3
CVE-2014-4199

vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary f…

Fix: after 10.0.3
Fix from $1,600 2014-08-28
Salt HIGH 7.2
CVE-2014-3563

Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to …

Fix: after 2014.1.9
Fix from $1,950 2014-08-22
Xml Dt MEDIUM 6.3
CVE-2014-5260

The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_#…

Fix: after 0.63
Fix from $1,600 2014-08-16
Linux Kernel MEDIUM 6.2
CVE-2014-5045

The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to …

Fix: 3.15.8+
Fix from $1,600 2014-08-01
Cloudforms 3.0 Management Engine MEDIUM 6.9
CVE-2014-3486

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
Vios MEDIUM 6.9
CVE-2014-3977

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this…

No fix yet
Fix from $1,600 2014-06-08