Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Enterprise Linux MEDIUM 6.7
CVE-2024-5742

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing…

Fix: 8.0+
Fix from $1,600 2024-06-12
Enterprise Linux MEDIUM 5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…

No fix yet
Fix from $1,600 2024-02-05
Enterprise Linux MEDIUM 6.7
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to …

Fix: 4.18+
Fix from $1,600 2022-08-26
Enterprise Linux MEDIUM 6.4
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response …

Fix: 4.18.0+
Fix from $1,600 2022-08-25
Openshift Container Platform HIGH 7.1
CVE-2020-27833

A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c…

Fix: after 4.7
Fix from $1,950 2021-05-14
Enterprise Linux MEDIUM 6.3
CVE-2021-20197

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When…

Fix: after 2.35
Fix from $1,600 2021-03-26
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-1869

The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on…

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool MEDIUM 6.5
CVE-2015-3147

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to w…

Patch available
Fix from $1,600 2020-01-14
Enterprise Linux MEDIUM 6.5
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…

Fix: 6.13.3+
Fix from $1,600 2019-12-13
Virtualization HIGH 8.1
CVE-2018-10897EPSS 6%

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil…

Fix: after 1.1.31
Fix from $1,950 2018-08-01
Enterprise Linux Desktop MEDIUM 6.7
CVE-2017-15097

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could…

Mitigation only
Fix from $1,600 2018-07-27
Satellite MEDIUM 5.5
CVE-2016-9595

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla…

Fix: 3.4.0+
Fix from $1,600 2018-07-27
Openshift HIGH 7.8
CVE-2013-4364

(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u…

Mitigation only
Fix from $1,950 2018-01-08
Enterprise Linux Desktop MEDIUM 5.5
CVE-2015-3149

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

Mitigation only
Fix from $1,600 2017-07-25
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-3315

Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sy…

Patch available
Fix from $1,950 2017-06-26
Ansible HIGH 7.8
CVE-2015-6240

The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.

Fix: after 1.9.1
Fix from $1,950 2017-06-07
Automatic Bug Reporting Tool MEDIUM 6.9
CVE-2015-5287

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges vi…

Fix: after 2.7.0
Fix from $1,600 2015-12-07
Cloudforms 3.0 Management Engine MEDIUM 6.9
CVE-2014-3486

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
Libvirt MEDIUM 5.8
CVE-2013-6456

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta…

Mitigation only
Fix from $1,600 2014-04-15
Enterprise Linux MEDIUM 6.3
CVE-2013-2561

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet…

No fix yet
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-2029

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arb…

Mitigation only
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-4214

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a sy…

Fix: after 3.5.1
Fix from $1,600 2013-11-23
Jboss Enterprise Web Server MEDIUM 6.9
CVE-2013-1976

The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0…

Mitigation only
Fix from $1,600 2013-07-09
Enterprise Linux MEDIUM 5.6
CVE-2012-3440

A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on …

No fix yet
Fix from $1,600 2012-08-08
Enterprise Linux MEDIUM 6.9
CVE-2009-1893

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar…

Mitigation only
Fix from $1,600 2009-07-17
Cluster Project MEDIUM 6.9
CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com…

Mitigation only
Fix from $1,600 2009-03-30
Cman MEDIUM 6.9
CVE-2008-4192

The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack…

Mitigation only
Fix from $1,600 2008-09-29
Enterprise Linux MEDIUM 6.2
CVE-2007-3103

The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary fil…

Patch available
Fix from $1,600 2007-07-15