Vulnerability index

Browse CVEs

50 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Debian Linux MEDIUM 6.7
CVE-2024-35235

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the…

Fix: after 2.4.8
Fix from $1,600 2024-06-11
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Debian Linux HIGH 8.1
CVE-2021-41072

squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst…

Patch available
Fix from $1,950 2021-09-14
Debian Linux HIGH 8.6
CVE-2021-37712

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution …

Fix: 1.0.1.1+
Fix from $1,950 2021-08-31
Debian Linux HIGH 8.6
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v…

Fix: 1.0.1.1 / 4.4.16+
Fix from $1,950 2021-08-31
Debian Linux MEDIUM 5.3
CVE-2021-28153

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a…

Fix: 2.66.8+
Fix from $1,600 2021-03-11
Debian Linux HIGH 7.8
CVE-2021-26720

avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att…

Fix: after 0.8-4
Fix from $1,950 2021-02-17
Debian Linux HIGH 8.8
CVE-2021-27229

Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.

Fix: 1.3.4+
Fix from $1,950 2021-02-16
Debian Linux MEDIUM 5.5
CVE-2020-28935

NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou…

Fix: 1.13.0 / 4.3.4+
Fix from $1,600 2020-12-07
X11 Common HIGH 7.8
CVE-2012-1093

The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during pac…

Fix: 1+
Fix from $1,950 2020-02-21
Debian Linux HIGH 8.1
CVE-2020-7040

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege …

Fix: after 3.5
Fix from $1,950 2020-01-21
Debian Linux MEDIUM 5.5
CVE-2013-4184

Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

Fix: 1.224+
Fix from $1,600 2019-12-10
Debian Linux HIGH 7.1
CVE-2011-3632

Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Debian Linux MEDIUM 5.5
CVE-2011-2924

foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mod…

Fix: after 4.0.12
Fix from $1,600 2019-11-19
Debian Linux MEDIUM 5.5
CVE-2011-2923

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode w…

Mitigation only
Fix from $1,600 2019-11-19
Debian Linux MEDIUM 5.5
CVE-2010-4817

pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

Fix: 0.3.5+
Fix from $1,600 2019-11-13
Debian Linux HIGH 7.8
CVE-2011-3618

atop: symlink attack possible due to insecure tempfile handling

Patch available
Fix from $1,950 2019-11-12
Debian Linux HIGH 7.5
CVE-2013-1809

Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo…

Fix: 3.4.0+
Fix from $1,950 2019-11-07
Lintian MEDIUM 6.3
CVE-2013-1429

Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

Fix: 2.5.10.5+
Fix from $1,600 2019-11-07
Debian Linux HIGH 8.2
CVE-2011-1408

ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

Fix: 3.20110608+
Fix from $1,950 2019-10-29
Debian Linux MEDIUM 5.9
CVE-2019-3902

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil…

Fix: 4.9+
Fix from $1,600 2019-04-22
Debian Linux HIGH 8.8
CVE-2018-14651

It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authentica…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Debian Linux HIGH 8.8
CVE-2018-10928

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gl…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.1
CVE-2018-13054

An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) ot…

Fix: after 3.8.6
Fix from $1,950 2018-07-02
Debian Linux CRITICAL 9.8
CVE-2018-1000544

rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …

Fix: after 1.2.1
Fix from $2,300 2018-06-26
Debian Linux HIGH 7.8
CVE-2018-10380

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

Fix: 5.12.6+
Fix from $1,950 2018-05-08
Debian Linux HIGH 8.8
CVE-2016-9602

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to…

Fix: 2.9+
Fix from $1,950 2018-04-26
Debian Linux HIGH 7.5
CVE-2017-2619EPSS 11%

Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file s…

Fix: 4.4.12 / 4.5.7+
Fix from $1,950 2018-03-12
Debian Linux HIGH 7.8
CVE-2017-18078

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl…

Fix: 237+
Fix from $1,950 2018-01-29
Postgresql Common HIGH 7.8
CVE-2016-1255

The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befo…

Patch available
Fix from $1,950 2017-12-05