Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
macOS MEDIUM 6.3
CVE-2024-27885

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7.…

Fix: 12.7.5 / 13.6.7+
Fix from $1,600 2024-06-10
macOS MEDIUM 5.5
CVE-2024-23285

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to prote…

Fix: 14.4+
Fix from $1,600 2024-03-08
Ipad Os HIGH 7.8
CVE-2023-42942

This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS…

Fix: 10.1 / 13.6.1+
Fix from $1,950 2024-02-21
macOS HIGH 7.5
CVE-2023-42844

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A…

Fix: 12.7.1 / 13.6.1+
Fix from $1,950 2023-10-25
Ipados MEDIUM 5.5
CVE-2023-41968

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, i…

Fix: 10.0 / 12.7+
Fix from $1,600 2023-09-27
Mac Os X MEDIUM 5.5
CVE-2022-22582EPSS 18%

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Securit…

Fix: 11.6.5 / 12.3+
Fix from $1,600 2023-02-27
macOS HIGH 7.8
CVE-2022-32905

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may…

Fix: 13.0+
Fix from $1,950 2022-11-01
Mac Os X HIGH 7.8
CVE-2022-26704

A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey …

Fix: 10.15.7 / 11.6.8+
Fix from $1,950 2022-05-26
Ipados HIGH 7.5
CVE-2022-22585

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS …

Fix: 8.4 / 11.6.3+
Fix from $1,950 2022-03-18
Iphone Os MEDIUM 5.5
CVE-2021-30968

A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS …

Fix: 8.3 / 10.15.7+
Fix from $1,600 2021-08-24
Ipados MEDIUM 5.5
CVE-2021-30855

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Securit…

Fix: 8.0 / 10.15.7+
Fix from $1,600 2021-08-24
Ipados HIGH 7.8
CVE-2020-10003

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macO…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2020-12-08
Ipados HIGH 7.8
CVE-2020-9901

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS …

Fix: 10.15.6 / 13.4.8+
Fix from $1,950 2020-10-22
Ipados HIGH 7.8
CVE-2020-9900

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS …

Fix: 6.2.8 / 10.15.6+
Fix from $1,950 2020-10-22
Tokend MEDIUM 6.1
CVE-2013-1867

Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability

Fix: after 03-2013
Fix from $1,600 2020-01-30
Ipados MEDIUM 5.5
CVE-2019-8789

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.…

Fix: 10.15.1 / 13.2+
Fix from $1,600 2019-12-18
Iphone Os MEDIUM 5.5
CVE-2019-8568

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.…

Fix: 5.2.1 / 10.14.5+
Fix from $1,600 2019-12-18
Mac Os X MEDIUM 5.5
CVE-2018-4112

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to o…

Fix: 10.13.4+
Fix from $1,600 2018-04-03
Iphone Os HIGH 7.8
CVE-2017-6981

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" c…

Fix: after 10.12.4
Fix from $1,950 2017-05-22
Iphone Os MEDIUM 5.5
CVE-2017-2390

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Iphone Os MEDIUM 5.5
CVE-2016-7619

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2016-4679

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat…

Fix: 3.1 / 10.0.1+
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.0
CVE-2015-5752

Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.

Fix: after 8.4
Fix from $1,600 2015-08-17
Mac Os X HIGH 7.8
CVE-2015-1130 KEVEPSS 10%

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via un…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Iphone Os HIGH 10.0
CVE-2014-4480

Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintende…

Fix: after 8.1.2
Fix from $1,950 2015-01-30
Tvos MEDIUM 6.3
CVE-2014-1272

CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by lever…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Cups MEDIUM 6.9
CVE-2009-0032

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrit…

Mitigation only
Fix from $1,600 2009-01-27
Cups MEDIUM 6.9
CVE-2008-5377

pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulner…

No fix yet
Fix from $1,600 2008-12-08
Mac Os X HIGH 7.6
CVE-2008-2311

Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attac…

Patch available
Fix from $1,950 2008-07-01
Mac Os X MEDIUM 6.8
CVE-2005-2714

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink …

Patch available
Fix from $1,600 2005-12-31