Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.7 CVE-2022-31258 In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink. Checkmk 1.6.0+ Fix from $1,6002022-05-20 HIGH 7.8 CVE-2022-30523 Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could … Password Manager 5.0.0.1270+ Fix from $1,9502022-05-16 HIGH 7.8 CVE-2022-23742 Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. … Endpoint Security Mitigation only Fix from $1,9502022-05-12 HIGH 7.5 CVE-2022-30333 KEVEPSS 99% RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by … Debian Linux 6.12+ Fix from $1,9502022-05-09 HIGH 8.1 CVE-2021-44052 An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero,… Qts 4.3.3.1945 / 4.3.4.1976+ Fix from $1,9502022-05-05 MEDIUM 6.7 CVE-2022-20085 In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with Sys… Android Mitigation only Fix from $1,6002022-05-03 HIGH 7.2 CVE-2022-20720 Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com… Ios Xe No fix yet Fix from $1,9502022-04-15 HIGH 7.8 CVE-2022-1256 A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through runn… Agent 5.7.6+ Fix from $1,9502022-04-14 HIGH 7.8 CVE-2022-22962 VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location d… Horizon 2203+ Fix from $1,9502022-04-11 MEDIUM 6.7 CVE-2022-20068 In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege wit… Android Mitigation only Fix from $1,6002022-04-11 HIGH 7.3 CVE-2022-27883 A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can… Antivirus For Mac after 11.5 Fix from $1,9502022-04-09 CRITICAL 9.8 CVE-2022-26612 In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR … Hadoop 3.2.3+ Fix from $2,3002022-04-07 HIGH 7.8 CVE-2021-27116 An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally. Beego after 2.0.2 Fix from $1,9502022-04-05 HIGH 7.8 CVE-2021-27117 An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks locally. Beego after 2.0.2 Fix from $1,9502022-04-05 HIGH 8.8 CVE-2022-0799 Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege e… Chrome 99.0.4844.51+ Fix from $1,9502022-04-05 HIGH 7.1 CVE-2022-27816 SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. Swhkd Patch available Fix from $1,9502022-03-30 HIGH 7.8 CVE-2022-27815 SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service. Swhkd Patch available Fix from $1,9502022-03-30 CRITICAL 9.8 CVE-2022-22995 The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combin… Fedora 5.19.117+ Fix from $2,3002022-03-25 HIGH 7.1 CVE-2022-26659 Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink i… Docker Desktop 4.6.0+ Fix from $1,9502022-03-25 HIGH 7.5 CVE-2022-22585 An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS … Ipados 8.4 / 11.6.3+ Fix from $1,9502022-03-18 MEDIUM 6.7 CVE-2022-20050 In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,6002022-03-10 HIGH 7.7 CVE-2022-22262 ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since t… Rog Live Service 1.3.3.0+ Fix from $1,9502022-03-01 HIGH 7.8 CVE-2022-24671 A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a fil… Antivirus after 11.0.2150 Fix from $1,9502022-02-24 HIGH 7.8 CVE-2022-24679 A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free… Apex One Patch available Fix from $1,9502022-02-24 HIGH 7.8 CVE-2022-24680 A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free… Apex One Patch available Fix from $1,9502022-02-24 HIGH 8.8 CVE-2021-44730 snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to … Snapd after 2.54.2 Fix from $1,9502022-02-17 MEDIUM 6.5 CVE-2022-25176 Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configur… Pipeline\ after 2648.va9433432b33c Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25177 Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline l… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25179 Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the conf… Pipeline\ after 706.vd43c65dec013 Fix from $1,6002022-02-15 HIGH 7.8 CVE-2022-0017 An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that en… Globalprotect 5.1.10 / 5.2.5+ Fix from $1,9502022-02-10