Vulnerability index

Browse CVEs

50 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.7 CVE-2024-35235 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the… Debian Linux after 2.4.8 Fix from $1,6002024-06-11 HIGH 7.5 CVE-2022-30333 KEVEPSS 99% RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by … Debian Linux 6.12+ Fix from $1,9502022-05-09 HIGH 8.1 CVE-2021-41072 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst… Debian Linux Patch available Fix from $1,9502021-09-14 HIGH 8.6 CVE-2021-37712 The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution … Debian Linux 1.0.1.1+ Fix from $1,9502021-08-31 HIGH 8.6 CVE-2021-37701 The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v… Debian Linux 1.0.1.1 / 4.4.16+ Fix from $1,9502021-08-31 MEDIUM 5.3 CVE-2021-28153 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a… Debian Linux 2.66.8+ Fix from $1,6002021-03-11 HIGH 7.8 CVE-2021-26720 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att… Debian Linux after 0.8-4 Fix from $1,9502021-02-17 HIGH 8.8 CVE-2021-27229 Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text. Debian Linux 1.3.4+ Fix from $1,9502021-02-16 MEDIUM 5.5 CVE-2020-28935 NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou… Debian Linux 1.13.0 / 4.3.4+ Fix from $1,6002020-12-07 HIGH 7.8 CVE-2012-1093 The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during pac… X11 Common 1+ Fix from $1,9502020-02-21 HIGH 8.1 CVE-2020-7040 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege … Debian Linux after 3.5 Fix from $1,9502020-01-21 MEDIUM 5.5 CVE-2013-4184 Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks Debian Linux 1.224+ Fix from $1,6002019-12-10 HIGH 7.1 CVE-2011-3632 Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. Debian Linux 0.1.2+ Fix from $1,9502019-11-26 MEDIUM 5.5 CVE-2011-2924 foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mod… Debian Linux after 4.0.12 Fix from $1,6002019-11-19 MEDIUM 5.5 CVE-2011-2923 foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode w… Debian Linux Mitigation only Fix from $1,6002019-11-19 MEDIUM 5.5 CVE-2010-4817 pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. Debian Linux 0.3.5+ Fix from $1,6002019-11-13 HIGH 7.8 CVE-2011-3618 atop: symlink attack possible due to insecure tempfile handling Debian Linux Patch available Fix from $1,9502019-11-12 HIGH 7.5 CVE-2013-1809 Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo… Debian Linux 3.4.0+ Fix from $1,9502019-11-07 MEDIUM 6.3 CVE-2013-1429 Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. Lintian 2.5.10.5+ Fix from $1,6002019-11-07 HIGH 8.2 CVE-2011-1408 ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. Debian Linux 3.20110608+ Fix from $1,9502019-10-29 MEDIUM 5.9 CVE-2019-3902 A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write fil… Debian Linux 4.9+ Fix from $1,6002019-04-22 HIGH 8.8 CVE-2018-14651 It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authentica… Debian Linux after 4.1.4 Fix from $1,9502018-10-31 HIGH 8.8 CVE-2018-10928 A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gl… Debian Linux 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 HIGH 8.1 CVE-2018-13054 An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) ot… Debian Linux after 3.8.6 Fix from $1,9502018-07-02 CRITICAL 9.8 CVE-2018-1000544 rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary … Debian Linux after 1.2.1 Fix from $2,3002018-06-26 HIGH 7.8 CVE-2018-10380 kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack. Debian Linux 5.12.6+ Fix from $1,9502018-05-08 HIGH 8.8 CVE-2016-9602 Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to… Debian Linux 2.9+ Fix from $1,9502018-04-26 HIGH 7.5 CVE-2017-2619EPSS 11% Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file s… Debian Linux 4.4.12 / 4.5.7+ Fix from $1,9502018-03-12 HIGH 7.8 CVE-2017-18078 systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl… Debian Linux 237+ Fix from $1,9502018-01-29 HIGH 7.8 CVE-2016-1255 The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befo… Postgresql Common Patch available Fix from $1,9502017-12-05