Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.9 CVE-2019-13636 In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c. Patch after 2.7.6 Fix from $1,6002019-07-17 HIGH 7.8 CVE-2019-1130 KEV An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o… Windows 10 1507 Patch available Fix from $1,9502019-07-15 HIGH 7.8 CVE-2019-1129 KEV An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o… Windows 10 1703 Patch available Fix from $1,9502019-07-15 MEDIUM 5.5 CVE-2019-1074 An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic l… Windows 10 Patch available Fix from $1,6002019-07-15 HIGH 7.1 CVE-2019-12571 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, … Private Internet Access Vpn Client No fix yet Fix from $1,9502019-07-11 HIGH 7.1 CVE-2019-12573 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attack… Private Internet Access Vpn Client No fix yet Fix from $1,9502019-07-11 HIGH 7.0 CVE-2019-13226 deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to tem… Fedora 1.1.3+ Fix from $1,9502019-07-04 MEDIUM 5.5 CVE-2019-13227 In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileg… Deepin Clone 1.1.3+ Fix from $1,6002019-07-04 MEDIUM 5.5 CVE-2019-13229 deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follow… Deepin Clone 1.1.3+ Fix from $1,6002019-07-04 HIGH 7.5 CVE-2019-13173 fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the syste… Fstream 1.0.12+ Fix from $1,9502019-07-02 MEDIUM 6.3 CVE-2019-1053 An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the … Windows 10 Patch available Fix from $1,6002019-06-12 HIGH 7.8 CVE-2019-1064 KEVEPSS 7% An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successf… Windows 10 1607 Patch available Fix from $1,9502019-06-12 HIGH 7.8 CVE-2019-1069 KEVEPSS 6% An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully … Windows 10 1507 Patch available Fix from $1,9502019-06-12 MEDIUM 6.3 CVE-2019-0986 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfu… Windows 10 Patch available Fix from $1,6002019-06-12 HIGH 7.1 CVE-2019-12749 dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less … Ubuntu Linux 1.10.28 / 1.12.16+ Fix from $1,9502019-06-11 HIGH 7.1 CVE-2019-12779 libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /t… Libqb 1.0.5+ Fix from $1,9502019-06-07 HIGH 7.5 CVE-2019-12209 Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and… Pam U2f Patch available Fix from $1,9502019-06-04 HIGH 8.1 CVE-2019-3567 In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali… Osquery 3.4.0+ Fix from $1,9502019-06-03 HIGH 8.8 CVE-2019-9949 Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a … My Cloud Firmware 2.31.183+ Fix from $1,9502019-05-23 HIGH 7.8 CVE-2019-0086 Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.… Converged Security Management Engine Firmware 3.1.65 / 11.8.65+ Fix from $1,9502019-05-17 HIGH 7.8 CVE-2019-0936 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevat… Windows 10 Patch available Fix from $1,9502019-05-16 MEDIUM 5.3 CVE-2019-5438 Path traversal using symlink in npm harp module versions <= 0.29.0. Harp after 0.29.0 Fix from $1,6002019-05-10 MEDIUM 5.5 CVE-2019-11879 The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web … Webrick Mitigation only Fix from $1,6002019-05-10 HIGH 7.1 CVE-2019-1836 A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authe… Nx Os Mitigation only Fix from $1,9502019-05-03 HIGH 7.5 CVE-2018-20834 A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarb… Tar 2.2.2 / 4.4.2+ Fix from $1,9502019-04-30 HIGH 7.0 CVE-2019-8454 A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another… Endpoint Security Mitigation only Fix from $1,9502019-04-29 HIGH 7.7 CVE-2019-11538EPSS 7% In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS pro… Connect Secure No fix yet Fix from $1,9502019-04-26 HIGH 7.5 CVE-2019-11502 snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, tha… Snapd 2.38+ Fix from $1,9502019-04-24 HIGH 7.5 CVE-2019-11503 snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the… Snapd 2.39+ Fix from $1,9502019-04-24 HIGH 7.8 CVE-2019-8452 A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 t… Endpoint Security after 15.4.062 Fix from $1,9502019-04-22