Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.5 CVE-2016-7619 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T… Iphone Os after 10.12.1 Fix from $1,6002017-02-20 MEDIUM 5.5 CVE-2016-4679 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat… Iphone Os 3.1 / 10.0.1+ Fix from $1,6002017-02-20 HIGH 7.8 CVE-2016-6253 mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary fil… Netbsd No fix yet Fix from $1,9502017-01-20 HIGH 7.8 CVE-2016-9566 base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink att… Nagios after 4.2.3 Fix from $1,9502016-12-15 HIGH 7.0 CVE-2016-6664 mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before … MySQL 5.5.41-37.0 / 5.5.51-38.2+ Fix from $1,9502016-12-13 HIGH 7.8 CVE-2016-1247 The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.0… Nginx after 1.10.1 Fix from $1,9502016-11-29 HIGH 7.8 CVE-2016-7490 The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could c… Studio Express No fix yet Fix from $1,9502016-11-10 HIGH 7.8 CVE-2016-3096 The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary file… Fedora after 1.9.6 Fix from $1,9502016-06-03 HIGH 8.4 CVE-2015-6566 zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vaca… Fedora after 7.2.0 Fix from $1,9502016-01-11 MEDIUM 6.9 CVE-2015-5287 The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges vi… Automatic Bug Reporting Tool after 2.7.0 Fix from $1,6002015-12-07 HIGH 7.2 CVE-2015-1338 kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symli… Ubuntu Linux after 2.18.1 Fix from $1,9502015-10-01 HIGH 7.2 CVE-2015-1335 lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (… Ubuntu Linux after 1.0.7 Fix from $1,9502015-10-01 MEDIUM 5.0 CVE-2015-5752 Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink. Iphone Os after 8.4 Fix from $1,6002015-08-17 MEDIUM 6.6 CVE-2015-3436 provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary fil… Zarafa Collaboration Platform after 7.1.12 Fix from $1,6002015-06-09 HIGH 7.8 CVE-2015-3629 Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file … Libcontainer No fix yet Fix from $1,9502015-05-18 HIGH 7.2 CVE-2015-3627 Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local us… Docker after 1.6.0 Fix from $1,9502015-05-18 HIGH 7.8 CVE-2015-1130 KEVEPSS 10% The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via un… Mac Os X 10.10.3+ Fix from $1,9502015-04-10 MEDIUM 5.8 CVE-2015-0556 Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive. Fedora after 3.10.22 Fix from $1,6002015-04-08 MEDIUM 6.4 CVE-2014-9512EPSS 6% rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path. Rsync No fix yet Fix from $1,6002015-02-12 HIGH 10.0 CVE-2014-4480 Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintende… Iphone Os after 8.1.2 Fix from $1,9502015-01-30 MEDIUM 5.8 CVE-2015-1038 p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive. Fedora No fix yet Fix from $1,6002015-01-21 HIGH 7.5 CVE-2014-6407 Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an im… Docker after 1.3.1 Fix from $1,9502014-12-12 MEDIUM 5.0 CVE-2014-3627 The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u… Hadoop Mitigation only Fix from $1,6002014-12-05 MEDIUM 5.0 CVE-2014-8585 Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (do… Download Manager No fix yet Fix from $1,6002014-11-04 MEDIUM 6.3 CVE-2014-4199 vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary f… Tools after 10.0.3 Fix from $1,6002014-08-28 HIGH 7.2 CVE-2014-3563 Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to … Salt after 2014.1.9 Fix from $1,9502014-08-22 MEDIUM 6.3 CVE-2014-5260 The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_#… Xml Dt after 0.63 Fix from $1,6002014-08-16 MEDIUM 6.2 CVE-2014-5045 The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to … Linux Kernel 3.15.8+ Fix from $1,6002014-08-01 MEDIUM 6.9 CVE-2014-3486 The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme… Cloudforms 3.0 Management Engine after 5.2.4 Fix from $1,6002014-07-07 MEDIUM 6.9 CVE-2014-3977 libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this… Vios No fix yet Fix from $1,6002014-06-08