Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
CRITICAL 9.8 CVE-2018-1000544 rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary … Debian Linux after 1.2.1 Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-12026 During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to rep… Passenger 5.3.2+ Fix from $2,3002018-06-17 MEDIUM 5.3 CVE-2018-5107 The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing pr… Firefox after 57.0.4 Fix from $1,6002018-06-11 HIGH 7.5 CVE-2018-12015EPSS 7% In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary… Ubuntu Linux 10.14.4+ Fix from $1,9502018-06-07 HIGH 7.8 CVE-2018-10380 kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack. Debian Linux 5.12.6+ Fix from $1,9502018-05-08 HIGH 7.8 CVE-2018-10722 In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify access to the %PROGRAMFILES%… Cylanceprotect 1470+ Fix from $1,9502018-05-04 HIGH 7.1 CVE-2013-0159 The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial … Fedora Patch available Fix from $1,9502018-05-01 HIGH 8.8 CVE-2016-9602 Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to… Debian Linux 2.9+ Fix from $1,9502018-04-26 MEDIUM 5.5 CVE-2018-4112 An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to o… Mac Os X 10.13.4+ Fix from $1,6002018-04-03 MEDIUM 5.5 CVE-2014-2312 The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid. Thermald 1.8+ Fix from $1,6002018-03-26 CRITICAL 9.9 CVE-2018-5225 In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (t… Bitbucket 5.4.8 / 5.5.8+ Fix from $2,3002018-03-22 MEDIUM 5.9 CVE-2018-1196 Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script includ… Spring Boot after 1.5.9 Fix from $1,6002018-03-19 CRITICAL 9.6 CVE-2017-1002101EPSS 12% In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volum… Kubernetes 1.7.14 / 1.8.9+ Fix from $2,3002018-03-13 HIGH 7.5 CVE-2018-1000073 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Rubygems after 2.5.0 Fix from $1,9502018-03-13 HIGH 7.5 CVE-2017-2619EPSS 11% Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file s… Debian Linux 4.4.12 / 4.5.7+ Fix from $1,9502018-03-12 HIGH 7.8 CVE-2015-0796 In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l… Open Buildservice 2.4.8 / 2.5.7+ Fix from $1,9502018-03-02 HIGH 7.5 CVE-2017-5188 The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director… Open Build Service after 2.7.3 Fix from $1,9502018-03-01 MEDIUM 5.5 CVE-2017-18188 OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by… Opentmpfiles after 0.1.3 Fix from $1,6002018-02-14 HIGH 7.8 CVE-2018-6954 systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of … Ubuntu Linux after 237 Fix from $1,9502018-02-13 HIGH 7.8 CVE-2014-3219 fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.… Fedora 2.1.1+ Fix from $1,9502018-02-09 HIGH 7.8 CVE-2017-18078 systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl… Debian Linux 237+ Fix from $1,9502018-01-29 MEDIUM 5.5 CVE-2017-15111 keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic li… Keycloak Httpd Client Install 0.8+ Fix from $1,6002018-01-20 MEDIUM 5.5 CVE-2014-4996 lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.… Vladtheenterprising Mitigation only Fix from $1,6002018-01-10 HIGH 7.8 CVE-2013-4364 (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u… Openshift Mitigation only Fix from $1,9502018-01-08 MEDIUM 5.5 CVE-2014-1859 (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local … Fedora after 1.8.0 Fix from $1,6002018-01-08 MEDIUM 5.5 CVE-2014-5509 clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$. Clipboard Patch available Fix from $1,6002018-01-08 HIGH 7.5 CVE-2017-1000420 Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite Syncthing after 0.14.33 Fix from $1,9502018-01-02 MEDIUM 5.5 CVE-2014-4978 The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1)… Fedora Patch available Fix from $1,6002017-12-29 HIGH 7.8 CVE-2016-1255 The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befo… Postgresql Common Patch available Fix from $1,9502017-12-05 HIGH 7.4 CVE-2017-15357 The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the up… Arq 5.9.7+ Fix from $1,9502017-12-01