Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2019-13636
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
Patch
after 2.7.6
HIGH 7.8
CVE-2019-1130 KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…
Windows 10 1507
Patch available
HIGH 7.8
CVE-2019-1129 KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…
Windows 10 1703
Patch available
MEDIUM 5.5
CVE-2019-1074
An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic l…
Windows 10
Patch available
HIGH 7.1
CVE-2019-12571
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, …
Private Internet Access Vpn Client
No fix yet
HIGH 7.1
CVE-2019-12573
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attack…
Private Internet Access Vpn Client
No fix yet
HIGH 7.0
CVE-2019-13226
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to tem…
Fedora
1.1.3+
MEDIUM 5.5
CVE-2019-13227
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileg…
Deepin Clone
1.1.3+
MEDIUM 5.5
CVE-2019-13229
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follow…
Deepin Clone
1.1.3+
HIGH 7.5
CVE-2019-13173
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the syste…
Fstream
1.0.12+
MEDIUM 6.3
CVE-2019-1053
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the …
Windows 10
Patch available
HIGH 7.8
CVE-2019-1064 KEVEPSS 7%
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successf…
Windows 10 1607
Patch available
HIGH 7.8
CVE-2019-1069 KEVEPSS 6%
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully …
Windows 10 1507
Patch available
MEDIUM 6.3
CVE-2019-0986
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfu…
Windows 10
Patch available
HIGH 7.1
CVE-2019-12749
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less …
Ubuntu Linux
1.10.28 / 1.12.16+
HIGH 7.1
CVE-2019-12779
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /t…
Libqb
1.0.5+
HIGH 7.5
CVE-2019-12209
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and…
Pam U2f
Patch available
HIGH 8.1
CVE-2019-3567
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali…
Osquery
3.4.0+
HIGH 8.8
CVE-2019-9949
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a …
My Cloud Firmware
2.31.183+
HIGH 7.8
CVE-2019-0086
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.…
Converged Security Management Engine Firmware
3.1.65 / 11.8.65+
HIGH 7.8
CVE-2019-0936
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevat…
Windows 10
Patch available
MEDIUM 5.3
CVE-2019-5438
Path traversal using symlink in npm harp module versions <= 0.29.0.
Harp
after 0.29.0
MEDIUM 5.5
CVE-2019-11879
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web …
Webrick
Mitigation only
HIGH 7.1
CVE-2019-1836
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authe…
Nx Os
Mitigation only
HIGH 7.5
CVE-2018-20834
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarb…
Tar
2.2.2 / 4.4.2+
HIGH 7.0
CVE-2019-8454
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another…
Endpoint Security
Mitigation only
HIGH 7.7
CVE-2019-11538EPSS 7%
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS pro…
Connect Secure
No fix yet
HIGH 7.5
CVE-2019-11502
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, tha…
Snapd
2.38+
HIGH 7.5
CVE-2019-11503
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the…
Snapd
2.39+
HIGH 7.8
CVE-2019-8452
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 t…
Endpoint Security
after 15.4.062