Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.5 CVE-2017-16611 In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, w… Debian Linux 1.5.4 / 2.0.3+ Fix from $1,6002017-12-01 HIGH 7.8 CVE-2017-7501 It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to writ… Rpm 4.13.0.3+ Fix from $1,9502017-11-22 MEDIUM 6.7 CVE-2017-12172 PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a … PostgreSQL Mitigation only Fix from $1,6002017-11-22 MEDIUM 5.5 CVE-2017-8806 The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 f… PostgreSQL Mitigation only Fix from $1,6002017-11-13 HIGH 8.8 CVE-2017-2916 An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network … Circle With Disney Firmware No fix yet Fix from $1,9502017-11-07 HIGH 7.8 CVE-2015-7529 sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive fi… Ubuntu Linux after 3.8 Fix from $1,9502017-11-06 MEDIUM 5.5 CVE-2011-2684 foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged … Foo2zjs Mitigation only Fix from $1,6002017-10-23 MEDIUM 5.5 CVE-2017-1301 IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporar… Tivoli Storage Manager Patch available Fix from $1,6002017-10-05 MEDIUM 6.1 CVE-2017-12258 A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame … Unified Communications Manager Mitigation only Fix from $1,6002017-10-05 HIGH 7.5 CVE-2017-1000115 Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository Debian Linux 4.3+ Fix from $1,9502017-10-05 MEDIUM 6.4 CVE-2017-7549 A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5… Instack Undercloud Mitigation only Fix from $1,6002017-09-21 HIGH 7.5 CVE-2015-5705 Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted fi… Fedora after 2.15.6 Fix from $1,9502017-09-06 MEDIUM 5.5 CVE-2015-3211 php-fpm allows local users to write to or create arbitrary files via a symlink attack. Php Fpm Mitigation only Fix from $1,6002017-08-25 MEDIUM 6.1 CVE-2015-5700 mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. Texlive Patch available Fix from $1,6002017-08-25 MEDIUM 6.1 CVE-2015-5701 mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE:… Texlive Patch available Fix from $1,6002017-08-25 MEDIUM 5.5 CVE-2015-3156 The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/… Trove after 2014.2.4 Fix from $1,6002017-08-11 MEDIUM 5.5 CVE-2015-3149 The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack. Enterprise Linux Desktop Mitigation only Fix from $1,6002017-07-25 HIGH 7.8 CVE-2015-3315 Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sy… Automatic Bug Reporting Tool Patch available Fix from $1,9502017-06-26 MEDIUM 6.7 CVE-2017-9525 In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to… Debian Linux after 3.0pl1-128. Fix from $1,6002017-06-09 HIGH 7.1 CVE-2016-3108 The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack. Pulp after 2.8.2-1 Fix from $1,9502017-06-08 HIGH 7.8 CVE-2017-8108 Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary… Lynis 2.5.0+ Fix from $1,9502017-06-08 HIGH 7.8 CVE-2015-6240 The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack. Ansible after 1.9.1 Fix from $1,9502017-06-07 HIGH 7.8 CVE-2015-7723 AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack. Fglrx Driver No fix yet Fix from $1,9502017-06-07 HIGH 7.8 CVE-2015-7724 AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix fo… Fglrx Driver after 15.7 Fix from $1,9502017-06-07 MEDIUM 5.5 CVE-2015-8326 The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user. Iptables Parse Module Patch available Fix from $1,6002017-06-07 HIGH 7.8 CVE-2017-6981 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" c… Iphone Os after 10.12.4 Fix from $1,9502017-05-22 MEDIUM 5.5 CVE-2016-10374 perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain outpu… Perltidy after 2016-03-02 Fix from $1,6002017-05-17 MEDIUM 5.5 CVE-2017-7418 ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSy… Proftpd after 1.3.5 Fix from $1,6002017-04-04 MEDIUM 5.5 CVE-2017-2390 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch… Iphone Os after 10.12.3 Fix from $1,6002017-04-02 HIGH 7.8 CVE-2016-9774 The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 1… Debian Linux Mitigation only Fix from $1,9502017-03-23