Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.8 CVE-2019-18897 A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; … Linux Enterprise Server Mitigation only Fix from $1,9502020-03-02 MEDIUM 5.5 CVE-2019-18901 A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE … Leap Mitigation only Fix from $1,6002020-03-02 HIGH 7.0 CVE-2019-3698 UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Ser… Nagios 3.0.6 / 3.5.1+ Fix from $1,9502020-02-28 HIGH 7.8 CVE-2012-1093 The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during pac… X11 Common 1+ Fix from $1,9502020-02-21 HIGH 7.8 CVE-2020-8950 The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted… User Experience Program after 1.0.0.1 Fix from $1,9502020-02-12 HIGH 7.1 CVE-2020-0730 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile… Windows 10 Patch available Fix from $1,9502020-02-11 HIGH 7.8 CVE-2020-0683 KEVEPSS 8% An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of… Windows 10 1507 Patch available Fix from $1,9502020-02-11 HIGH 7.8 CVE-2019-11481 Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic … Ubuntu Linux No fix yet Fix from $1,9502020-02-08 HIGH 7.8 CVE-2020-7221 mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are perfor… MariaDB after 10.4.11 Fix from $1,9502020-02-04 MEDIUM 5.7 CVE-2019-11251 The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provid… Kubernetes 1.13.11 / 1.14.7+ Fix from $1,6002020-02-03 MEDIUM 5.5 CVE-2020-8095 A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial… Total Security 2020 24.9+ Fix from $1,6002020-01-30 MEDIUM 6.1 CVE-2013-1866 OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability Opensc 0.13.0+ Fix from $1,6002020-01-30 MEDIUM 6.1 CVE-2013-1867 Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability Tokend after 03-2013 Fix from $1,6002020-01-30 MEDIUM 5.5 CVE-2012-6114 The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/… Git Extras Mitigation only Fix from $1,6002020-01-28 HIGH 7.8 CVE-2019-3699 UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate fr… Privoxy 3.0.28-lp151.1.1 / 3.0.28-2.1+ Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-3697 UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user g… Gnump3d after 3.0 Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-3694 A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from us… Munin after 2.0.49-4.2 Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-3693 A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1… Mailman 2.1.15-9.6.15.1 / 2.1.17-3.11.1+ Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-3692 The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via sym… Inn after 2.6.2-2.2 Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-3691 A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attack… Munge 0.5.13-4.3.1 / 0.5.13-6.1+ Fix from $1,9502020-01-23 HIGH 7.8 CVE-2019-18898 UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local a… Trousers 0.3.14-6.3.1 / 0.3.14-7.1+ Fix from $1,9502020-01-23 HIGH 8.1 CVE-2020-7040 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege … Debian Linux after 3.5 Fix from $1,9502020-01-21 HIGH 7.0 CVE-2019-18932 log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tm… Squid Analysis Report Generator after 2.3.11 Fix from $1,9502020-01-21 HIGH 7.8 CVE-2020-0638 KEV An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker wo… Windows 10 1709 Patch available Fix from $1,9502020-01-14 MEDIUM 5.5 CVE-2020-0616 A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. Windows 10 Patch available Fix from $1,6002020-01-14 HIGH 7.8 CVE-2015-1869 The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on… Automatic Bug Reporting Tool Patch available Fix from $1,9502020-01-14 MEDIUM 6.5 CVE-2015-3147 daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to w… Automatic Bug Reporting Tool Patch available Fix from $1,6002020-01-14 HIGH 7.8 CVE-2019-16896 In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, al… K7 Ultimate Security No fix yet Fix from $1,9502019-12-27 HIGH 7.5 CVE-2019-19695 A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symb… Antivirus after 9.0.1379 Fix from $1,9502019-12-24 HIGH 7.5 CVE-2019-8463 A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file t… Endpoint Security Clients Patch available Fix from $1,9502019-12-23