Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.5 CVE-2021-21300EPSS 89% Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as… Git 2.17.6 / 2.18.5+ Fix from $1,9502021-03-09 MEDIUM 5.5 CVE-2021-24084 Windows Mobile Device Management Information Disclosure Vulnerability Windows 10 Patch available Fix from $1,6002021-02-25 HIGH 7.8 CVE-2020-12878 Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, rel… Connectport X2e Firmware 3.2.30.6+ Fix from $1,9502021-02-18 HIGH 7.8 CVE-2021-26720 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att… Debian Linux after 0.8-4 Fix from $1,9502021-02-17 HIGH 8.8 CVE-2021-27229 Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text. Debian Linux 1.3.4+ Fix from $1,9502021-02-16 MEDIUM 6.1 CVE-2021-23873 Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbi… Total Protection 16.0.30+ Fix from $1,6002021-02-10 MEDIUM 6.5 CVE-2021-21131EPSS 8% Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,6002021-02-09 HIGH 7.8 CVE-2021-21117 Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalatio… Chrome 88.0.4324.96+ Fix from $1,9502021-02-09 HIGH 8.1 CVE-2021-21125EPSS 8% Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem r… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,9502021-02-09 MEDIUM 5.5 CVE-2020-36241 autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extra… Fedora after 0.2.4 Fix from $1,6002021-02-05 MEDIUM 5.5 CVE-2020-8585 OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY … Oncommand Unified Manager 5.2.5+ Fix from $1,6002021-01-28 HIGH 7.7 CVE-2021-21272 ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go … Oras 0.9.0+ Fix from $1,9502021-01-25 HIGH 7.5 CVE-2021-1278 Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against … Ios Xe Sd Wan Mitigation only Fix from $1,9502021-01-20 HIGH 7.5 CVE-2020-36193 KEVEPSS 71% Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue … Archive Tar 7.78 / 8.9.13+ Fix from $1,9502021-01-18 MEDIUM 6.5 CVE-2021-1145 A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbi… Staros 21.19.7+ Fix from $1,6002021-01-13 MEDIUM 6.5 CVE-2021-21602 Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by fol… Jenkins after 2.274 Fix from $1,6002021-01-13 HIGH 7.8 CVE-2021-23240 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacin… Fedora 1.8.32 / 1.9.5+ Fix from $1,9502021-01-12 MEDIUM 6.5 CVE-2020-27643 The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify fil… Client Mitigation only Fix from $1,6002020-12-29 CRITICAL 9.8 CVE-2020-27172 An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file restore mechanism to achieve arbit… G Data 25.5.9.25+ Fix from $2,3002020-12-28 HIGH 7.8 CVE-2020-35766 The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (r… Opendkim after 2.10.3 Fix from $1,9502020-12-28 HIGH 7.1 CVE-2020-28641 In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system. Endpoint Protection 1.2.0.849+ Fix from $1,9502020-12-22 MEDIUM 6.1 CVE-2020-26277 DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously… Dbdeployer 1.58.2+ Fix from $1,6002020-12-21 HIGH 7.8 CVE-2020-10003 An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macO… Ipados 7.1 / 11.0.1+ Fix from $1,9502020-12-08 MEDIUM 5.5 CVE-2020-28935 NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou… Debian Linux 1.13.0 / 4.3.4+ Fix from $1,6002020-12-07 HIGH 7.5 CVE-2020-29529 HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with … Go Slug 0.5.0+ Fix from $1,9502020-12-03 MEDIUM 6.1 CVE-2020-5797 UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network … Archer C9 Firmware No fix yet Fix from $1,6002020-11-21 HIGH 7.8 CVE-2020-25989 Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may al… Pritunl Client Electron after 1.2.2550.20 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-27697 Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-pr… Antivirus\+ Security 2020 after 16.0 Fix from $1,9502020-11-18 HIGH 7.8 CVE-2020-23968 Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSS… International Sign\&go No fix yet Fix from $1,9502020-11-10 MEDIUM 6.2 CVE-2020-5795 UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access… Archer A7 Firmware No fix yet Fix from $1,6002020-11-06