Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.9 CVE-2019-3902 A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil… Debian Linux 4.9+ Fix from $1,6002019-04-22 HIGH 7.1 CVE-2019-8455 A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all u… Zonealarm after 15.4.062 Fix from $1,9502019-04-17 HIGH 7.8 CVE-2019-0841 KEVEPSS 41% An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o… Windows 10 1703 Patch available Fix from $1,9502019-04-09 MEDIUM 5.5 CVE-2019-1002101EPSS 13% The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside … Kubernetes 1.11.9 / 1.12.7+ Fix from $1,6002019-04-01 HIGH 7.0 CVE-2019-5674 NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system an… Geforce Experience 3.18+ Fix from $1,9502019-03-28 MEDIUM 5.5 CVE-2018-17955 In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection Yast2 Multipath 4.1.1+ Fix from $1,6002019-03-15 MEDIUM 5.5 CVE-2018-19637 Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symli… Supportutils 3.1-5.7.1+ Fix from $1,6002019-03-05 HIGH 7.8 CVE-2019-5665 NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does… Gpu Driver Patch available Fix from $1,9502019-02-27 HIGH 7.0 CVE-2019-8372 The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physi… Lha.sys 1.1.1811.2101+ Fix from $1,9502019-02-18 HIGH 7.8 CVE-2019-0572EPSS 25% An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Se… Windows 10 Patch available Fix from $1,9502019-01-08 HIGH 7.8 CVE-2019-0574EPSS 19% An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Se… Windows 10 Patch available Fix from $1,9502019-01-08 HIGH 7.8 CVE-2018-1780 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root acc… Db2 Mitigation only Fix from $1,9502018-11-09 HIGH 7.8 CVE-2018-1781 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploit… Db2 Mitigation only Fix from $1,9502018-11-09 HIGH 7.8 CVE-2018-1834 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to… Db2 Mitigation only Fix from $1,9502018-11-09 HIGH 8.8 CVE-2018-14651 It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authentica… Debian Linux after 4.1.4 Fix from $1,9502018-10-31 HIGH 7.5 CVE-2018-17567 Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include… Jekyll after 3.8.3 Fix from $1,9502018-09-28 HIGH 8.8 CVE-2018-10928 A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gl… Debian Linux 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 HIGH 7.0 CVE-2018-6557 The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled te… Ubuntu Linux Mitigation only Fix from $1,9502018-08-21 HIGH 7.5 CVE-2011-2765 pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overw… Pyro 3.15+ Fix from $1,9502018-08-20 MEDIUM 6.5 CVE-2018-15351 Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware vers… 24f2xg Router Firmware after 3.5.30.1118 Fix from $1,6002018-08-17 HIGH 7.8 CVE-2017-7500 It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownersh… Rpm 4.13.0.2+ Fix from $1,9502018-08-13 HIGH 8.1 CVE-2018-10897EPSS 6% A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil… Virtualization after 1.1.31 Fix from $1,9502018-08-01 HIGH 7.8 CVE-2016-8641 A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing th… Nagios Patch available Fix from $1,9502018-08-01 MEDIUM 6.7 CVE-2017-15097 Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-07-27 MEDIUM 5.5 CVE-2016-9595 A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla… Satellite 3.4.0+ Fix from $1,6002018-07-27 MEDIUM 6.5 CVE-2018-14335EPSS 13% An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of t… H2 No fix yet Fix from $1,6002018-07-24 MEDIUM 5.5 CVE-2014-4150 The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48l… Scheme48 Patch available Fix from $1,6002018-07-20 MEDIUM 5.5 CVE-2014-0243 Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job. Check Mk after 1.2.5 Fix from $1,6002018-07-19 HIGH 7.5 CVE-2018-11637 Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary file… Powermedia Xms after 3.5 Fix from $1,9502018-07-03 HIGH 8.1 CVE-2018-13054 An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) ot… Debian Linux after 3.8.6 Fix from $1,9502018-07-02