Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.1 CVE-2019-19693 The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive informatio… Antivirus\+ Security 2020 16.0.1249+ Fix from $1,9502019-12-20 MEDIUM 5.5 CVE-2019-8789 A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.… Ipados 10.15.1 / 13.2+ Fix from $1,6002019-12-18 MEDIUM 5.5 CVE-2019-8568 A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.… Iphone Os 5.2.1 / 10.14.5+ Fix from $1,6002019-12-18 HIGH 7.8 CVE-2019-10773 In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially craft… Yarn 1.21.1+ Fix from $1,9502019-12-16 MEDIUM 6.5 CVE-2019-16775 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of… Enterprise Linux 6.13.3+ Fix from $1,6002019-12-13 HIGH 7.8 CVE-2019-18232 SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a se… Sentinel Ldk License Manager 7.101+ Fix from $1,9502019-12-11 HIGH 7.8 CVE-2019-1483 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an… Windows 10 Patch available Fix from $1,9502019-12-10 MEDIUM 5.5 CVE-2013-4184 Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks Debian Linux 1.224+ Fix from $1,6002019-12-10 HIGH 7.1 CVE-2019-18575 Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploi… Command\|configure 4.2.1+ Fix from $1,9502019-12-06 CRITICAL 9.8 CVE-2019-7183 This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to… Qts Mitigation only Fix from $2,3002019-12-05 MEDIUM 5.5 CVE-2019-3749 Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges … Command Update 3.1+ Fix from $1,6002019-12-03 MEDIUM 5.5 CVE-2019-3750 Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges … Command Update 3.1+ Fix from $1,6002019-12-03 HIGH 7.1 CVE-2011-3632 Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. Debian Linux 0.1.2+ Fix from $1,9502019-11-26 HIGH 7.1 CVE-2011-3351 openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated… Openvas Scanner 2011-09-11+ Fix from $1,9502019-11-25 MEDIUM 5.5 CVE-2019-17445 An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operatio… Eda Agent after 10.2.26 Fix from $1,6002019-11-22 HIGH 7.8 CVE-2019-19191 Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the sh… Service Provider 3.1.0+ Fix from $1,9502019-11-21 MEDIUM 5.5 CVE-2014-1938 python-rply before 0.7.4 insecurely creates temporary files. Rply 0.7.4+ Fix from $1,6002019-11-21 MEDIUM 5.5 CVE-2011-2924 foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mod… Debian Linux after 4.0.12 Fix from $1,6002019-11-19 MEDIUM 5.5 CVE-2011-2923 foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode w… Debian Linux Mitigation only Fix from $1,6002019-11-19 HIGH 7.8 CVE-2008-7273 A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling. Iceweasel Firegpg 0.6+ Fix from $1,9502019-11-18 MEDIUM 5.5 CVE-2010-4817 pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. Debian Linux 0.3.5+ Fix from $1,6002019-11-13 HIGH 8.6 CVE-2019-18837 An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to… Fedora 0.10.5+ Fix from $1,9502019-11-13 HIGH 7.5 CVE-2013-4655 Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service. N900 Firmware No fix yet Fix from $1,9502019-11-13 HIGH 7.8 CVE-2019-1422 An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Ele… Windows 10 Patch available Fix from $1,9502019-11-12 HIGH 7.8 CVE-2019-1423 An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations, aka 'Windows Eleva… Windows 10 Patch available Fix from $1,9502019-11-12 MEDIUM 6.5 CVE-2019-1425 An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual S… Visual Studio 2017 Patch available Fix from $1,6002019-11-12 HIGH 7.8 CVE-2019-1385 KEV An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc… Windows 10 1709 Patch available Fix from $1,9502019-11-12 HIGH 7.8 CVE-2011-3618 atop: symlink attack possible due to insecure tempfile handling Debian Linux Patch available Fix from $1,9502019-11-12 MEDIUM 5.5 CVE-2011-5271 Pacemaker before 1.1.6 configure script creates temporary files insecurely Pacemaker 1.1.6+ Fix from $1,6002019-11-12 CRITICAL 9.8 CVE-2019-18658 In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously desig… Helm 2.15.2+ Fix from $2,3002019-11-12