Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.5 CVE-2009-0035 alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/als… Alsa 1.0.20+ Fix from $1,6002019-11-09 HIGH 7.5 CVE-2013-1809 Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo… Debian Linux 3.4.0+ Fix from $1,9502019-11-07 MEDIUM 6.3 CVE-2013-1429 Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. Lintian 2.5.10.5+ Fix from $1,6002019-11-07 MEDIUM 5.5 CVE-2019-18645 The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to pri… Anti Virus No fix yet Fix from $1,6002019-10-31 MEDIUM 6.5 CVE-2010-0398 The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack. Autokey 0.61.3+ Fix from $1,6002019-10-30 HIGH 7.1 CVE-2010-2064 rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr. Rpcbind Mitigation only Fix from $1,9502019-10-29 HIGH 8.2 CVE-2011-1408 ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. Debian Linux 3.20110608+ Fix from $1,9502019-10-29 HIGH 7.5 CVE-2012-2945 Hadoop 1.0.3 contains a symlink vulnerability. Hadoop No fix yet Fix from $1,9502019-10-29 MEDIUM 5.5 CVE-2019-18466 An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the… Libpod 1.6.0+ Fix from $1,6002019-10-28 HIGH 7.1 CVE-2019-15627 Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability… Deep Security No fix yet Fix from $1,9502019-10-17 HIGH 7.8 CVE-2019-1339 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manag… Windows 10 Patch available Fix from $1,9502019-10-10 HIGH 7.8 CVE-2019-1315 KEV An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manag… Windows 10 1607 Patch available Fix from $1,9502019-10-10 HIGH 7.3 CVE-2019-1317 A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. Windows 10 Patch available Fix from $1,9502019-10-10 MEDIUM 6.8 CVE-2019-12672 A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to… iOS Mitigation only Fix from $1,6002019-09-25 HIGH 7.8 CVE-2019-1267 An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable … Windows 10 Patch available Fix from $1,9502019-09-11 MEDIUM 5.5 CVE-2019-1270 An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Mic… Windows 10 Patch available Fix from $1,6002019-09-11 HIGH 7.8 CVE-2019-1280EPSS 19% A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who … Windows 10 Patch available Fix from $1,9502019-09-11 HIGH 7.8 CVE-2019-1253 KEVEPSS 12% An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an… Windows 10 1703 Patch available Fix from $1,9502019-09-11 HIGH 7.8 CVE-2019-11396 An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuratio… Free Security Suite after 2.0.6.13175 Fix from $1,9502019-08-29 HIGH 7.5 CVE-2018-20990 An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive. Tar 0.4.16+ Fix from $1,9502019-08-26 MEDIUM 6.7 CVE-2018-1632 IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu… Informix Dynamic Server Mitigation only Fix from $1,6002019-08-20 MEDIUM 6.7 CVE-2018-1633 IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu… Informix Dynamic Server Mitigation only Fix from $1,6002019-08-20 MEDIUM 6.7 CVE-2018-1634 IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu… Informix Dynamic Server Mitigation only Fix from $1,6002019-08-20 MEDIUM 6.7 CVE-2018-1630 IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu… Informix Dynamic Server Mitigation only Fix from $1,6002019-08-20 MEDIUM 6.7 CVE-2018-1631 IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges throu… Informix Dynamic Server Mitigation only Fix from $1,6002019-08-20 HIGH 7.5 CVE-2019-1188 A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who… Windows 10 Patch available Fix from $1,9502019-08-14 HIGH 7.8 CVE-2019-5683 NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the user mode video driver trace logger component. When an attacker has … Gpu Driver Mitigation only Fix from $1,9502019-08-06 HIGH 7.2 CVE-2019-10152 A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who h… Libpod 1.4.0+ Fix from $1,9502019-07-30 HIGH 7.8 CVE-2019-13382 UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorde… Snagit No fix yet Fix from $1,9502019-07-26 HIGH 7.5 CVE-2019-13915 b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and ru… Wide 1.6.0+ Fix from $1,9502019-07-18