Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.7 CVE-2024-5742 A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing… Enterprise Linux 8.0+ Fix from $1,6002024-06-12 MEDIUM 5.3 CVE-2023-7216 A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a… Enterprise Linux No fix yet Fix from $1,6002024-02-05 MEDIUM 6.7 CVE-2021-35939 It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to … Enterprise Linux 4.18+ Fix from $1,6002022-08-26 MEDIUM 6.4 CVE-2021-35937 A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response … Enterprise Linux 4.18.0+ Fix from $1,6002022-08-25 HIGH 7.1 CVE-2020-27833 A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c… Openshift Container Platform after 4.7 Fix from $1,9502021-05-14 MEDIUM 6.3 CVE-2021-20197 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When… Enterprise Linux after 2.35 Fix from $1,6002021-03-26 HIGH 7.8 CVE-2015-1869 The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on… Automatic Bug Reporting Tool Patch available Fix from $1,9502020-01-14 MEDIUM 6.5 CVE-2015-3147 daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to w… Automatic Bug Reporting Tool Patch available Fix from $1,6002020-01-14 MEDIUM 6.5 CVE-2019-16775 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of… Enterprise Linux 6.13.3+ Fix from $1,6002019-12-13 HIGH 8.1 CVE-2018-10897EPSS 6% A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil… Virtualization after 1.1.31 Fix from $1,9502018-08-01 MEDIUM 6.7 CVE-2017-15097 Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-07-27 MEDIUM 5.5 CVE-2016-9595 A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla… Satellite 3.4.0+ Fix from $1,6002018-07-27 HIGH 7.8 CVE-2013-4364 (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u… Openshift Mitigation only Fix from $1,9502018-01-08 MEDIUM 5.5 CVE-2015-3149 The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack. Enterprise Linux Desktop Mitigation only Fix from $1,6002017-07-25 HIGH 7.8 CVE-2015-3315 Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sy… Automatic Bug Reporting Tool Patch available Fix from $1,9502017-06-26 HIGH 7.8 CVE-2015-6240 The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack. Ansible after 1.9.1 Fix from $1,9502017-06-07 MEDIUM 6.9 CVE-2015-5287 The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges vi… Automatic Bug Reporting Tool after 2.7.0 Fix from $1,6002015-12-07 MEDIUM 6.9 CVE-2014-3486 The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme… Cloudforms 3.0 Management Engine after 5.2.4 Fix from $1,6002014-07-07 MEDIUM 5.8 CVE-2013-6456 The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta… Libvirt Mitigation only Fix from $1,6002014-04-15 MEDIUM 6.3 CVE-2013-2561 OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet… Enterprise Linux No fix yet Fix from $1,6002013-11-23 MEDIUM 6.3 CVE-2013-2029 nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arb… Openstack Mitigation only Fix from $1,6002013-11-23 MEDIUM 6.3 CVE-2013-4214 rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a sy… Openstack after 3.5.1 Fix from $1,6002013-11-23 MEDIUM 6.9 CVE-2013-1976 The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0… Jboss Enterprise Web Server Mitigation only Fix from $1,6002013-07-09 MEDIUM 5.6 CVE-2012-3440 A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on … Enterprise Linux No fix yet Fix from $1,6002012-08-08 MEDIUM 6.9 CVE-2009-1893 The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar… Enterprise Linux Mitigation only Fix from $1,6002009-07-17 MEDIUM 6.9 CVE-2008-6552 Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com… Cluster Project Mitigation only Fix from $1,6002009-03-30 MEDIUM 6.9 CVE-2008-4192 The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack… Cman Mitigation only Fix from $1,6002008-09-29 MEDIUM 6.2 CVE-2007-3103 The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary fil… Enterprise Linux Patch available Fix from $1,6002007-07-15