Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2018-1000544
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …
Debian Linux
after 1.2.1
CRITICAL 9.8
CVE-2018-12026
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to rep…
Passenger
5.3.2+
MEDIUM 5.3
CVE-2018-5107
The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing pr…
Firefox
after 57.0.4
HIGH 7.5
CVE-2018-12015EPSS 7%
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary…
Ubuntu Linux
10.14.4+
HIGH 7.8
CVE-2018-10380
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
Debian Linux
5.12.6+
HIGH 7.8
CVE-2018-10722
In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify access to the %PROGRAMFILES%…
Cylanceprotect
1470+
HIGH 7.1
CVE-2013-0159
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial …
Fedora
Patch available
HIGH 8.8
CVE-2016-9602
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to…
Debian Linux
2.9+
MEDIUM 5.5
CVE-2018-4112
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to o…
Mac Os X
10.13.4+
MEDIUM 5.5
CVE-2014-2312
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
Thermald
1.8+
CRITICAL 9.9
CVE-2018-5225
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (t…
Bitbucket
5.4.8 / 5.5.8+
MEDIUM 5.9
CVE-2018-1196
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script includ…
Spring Boot
after 1.5.9
CRITICAL 9.6
CVE-2017-1002101EPSS 12%
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volum…
Kubernetes
1.7.14 / 1.8.9+
HIGH 7.5
CVE-2018-1000073
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…
Rubygems
after 2.5.0
HIGH 7.5
CVE-2017-2619EPSS 11%
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file s…
Debian Linux
4.4.12 / 4.5.7+
HIGH 7.8
CVE-2015-0796
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l…
Open Buildservice
2.4.8 / 2.5.7+
HIGH 7.5
CVE-2017-5188
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director…
Open Build Service
after 2.7.3
MEDIUM 5.5
CVE-2017-18188
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by…
Opentmpfiles
after 0.1.3
HIGH 7.8
CVE-2018-6954
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of …
Ubuntu Linux
after 237
HIGH 7.8
CVE-2014-3219
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.…
Fedora
2.1.1+
HIGH 7.8
CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl…
Debian Linux
237+
MEDIUM 5.5
CVE-2017-15111
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic li…
Keycloak Httpd Client Install
0.8+
MEDIUM 5.5
CVE-2014-4996
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.…
Vladtheenterprising
Mitigation only
HIGH 7.8
CVE-2013-4364
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u…
Openshift
Mitigation only
MEDIUM 5.5
CVE-2014-1859
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local …
Fedora
after 1.8.0
MEDIUM 5.5
CVE-2014-5509
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
Clipboard
Patch available
HIGH 7.5
CVE-2017-1000420
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
Syncthing
after 0.14.33
MEDIUM 5.5
CVE-2014-4978
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1)…
Fedora
Patch available
HIGH 7.8
CVE-2016-1255
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befo…
Postgresql Common
Patch available
HIGH 7.4
CVE-2017-15357
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the up…
Arq
5.9.7+