Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 8.1 CVE-2022-36113 Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on… Cargo 0.65.0+ Fix from $1,9502022-09-14 MEDIUM 5.5 CVE-2022-0029 An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the … Cortex Xdr Agent 5.0.12 / 7.5.101+ Fix from $1,6002022-09-14 HIGH 7.8 CVE-2022-2897 Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation.. Scadapro Client Mitigation only Fix from $1,9502022-08-31 MEDIUM 5.5 CVE-2022-2898 Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service conditio… Scadapro Client Mitigation only Fix from $1,6002022-08-31 MEDIUM 6.7 CVE-2021-35939 It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to … Enterprise Linux 4.18+ Fix from $1,6002022-08-26 MEDIUM 6.4 CVE-2021-35937 A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response … Enterprise Linux 4.18.0+ Fix from $1,6002022-08-25 MEDIUM 6.7 CVE-2021-35938 A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged… Fedora 4.18.0+ Fix from $1,6002022-08-25 CRITICAL 9.8 CVE-2022-34960 The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations … Routeros No fix yet Fix from $2,3002022-08-25 HIGH 7.8 CVE-2021-23177 An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacke… Fedora Patch available Fix from $1,9502022-08-23 HIGH 7.8 CVE-2021-31566 An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file ou… Fedora Patch available Fix from $1,9502022-08-23 HIGH 7.8 CVE-2022-36336 A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker … Apex One Mitigation only Fix from $1,9502022-07-30 MEDIUM 5.5 CVE-2022-35631 On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have th… Velociraptor 0.6.5-2+ Fix from $1,6002022-07-29 HIGH 7.8 CVE-2022-31250 A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to … Tumbleweed 6.4.2-1.1+ Fix from $1,9502022-07-20 HIGH 7.1 CVE-2022-32450 AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad… Anydesk No fix yet Fix from $1,9502022-07-18 MEDIUM 6.7 CVE-2022-21770 In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System exe… Android Mitigation only Fix from $1,6002022-07-06 HIGH 7.8 CVE-2022-2145 Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the W… Warp 2022.5.309.0+ Fix from $1,9502022-06-28 MEDIUM 6.7 CVE-2021-42056 Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attack… Safenet Authentication Client after 10.7.7 Fix from $1,6002022-06-24 HIGH 7.8 CVE-2022-34008 Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS… Antivirus No fix yet Fix from $1,9502022-06-21 HIGH 7.5 CVE-2022-25856 The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read()… Argo Events 1.7.1+ Fix from $1,9502022-06-17 HIGH 7.8 CVE-2021-25261 Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code wit… Yandex Browser 22.5.0.862+ Fix from $1,9502022-06-15 HIGH 7.8 CVE-2022-28225 Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code wit… Yandex Browser 22.3.3.684+ Fix from $1,9502022-06-15 HIGH 7.8 CVE-2022-31216 Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr… Automation Builder 2.7.1+ Fix from $1,9502022-06-15 HIGH 7.8 CVE-2022-31217 Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr… Automation Builder 2.7.1+ Fix from $1,9502022-06-15 HIGH 7.8 CVE-2022-31218 Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr… Automation Builder 2.7.1+ Fix from $1,9502022-06-15 HIGH 7.8 CVE-2022-31219 Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr… Automation Builder 2.7.1+ Fix from $1,9502022-06-15 HIGH 8.4 CVE-2021-41641 Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be use… Deno after 1.14.0 Fix from $1,9502022-06-12 HIGH 7.1 CVE-2022-30687 Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the prod… Maximum Security 2022 Mitigation only Fix from $1,9502022-05-27 HIGH 7.8 CVE-2022-26704 A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey … Mac Os X 10.15.7 / 11.6.8+ Fix from $1,9502022-05-26 HIGH 8.6 CVE-2022-30321 go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i… Go Getter after 1.5.11 Fix from $1,9502022-05-25 HIGH 7.0 CVE-2022-31466 Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escal… Total Security 12.1.1.27+ Fix from $1,9502022-05-23