Vulnerabilities (CVE)

Filtered by CWE-59
Total 1343 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1002101 1 Kubernetes 1 Kubernetes 2024-11-21 5.5 MEDIUM 8.8 HIGH
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
CVE-2017-1000420 1 Syncthing 1 Syncthing 2024-11-21 6.4 MEDIUM 7.5 HIGH
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
CVE-2016-9602 2 Debian, Qemu 2 Debian Linux, Qemu 2024-11-21 9.0 HIGH 7.6 HIGH
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
CVE-2016-9595 2 Redhat, Theforeman 3 Satellite, Satellite Capsule, Katello 2024-11-21 3.6 LOW 7.3 HIGH
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
CVE-2016-8641 1 Nagios 1 Nagios 2024-11-21 7.2 HIGH 6.7 MEDIUM
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.
CVE-2015-3147 1 Redhat 7 Automatic Bug Reporting Tool, Enterprise Linux Desktop, Enterprise Linux Server and 4 more 2024-11-21 4.9 MEDIUM 6.5 MEDIUM
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
CVE-2015-1869 1 Redhat 1 Automatic Bug Reporting Tool 2024-11-21 7.2 HIGH 7.8 HIGH
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
CVE-2015-0796 1 Opensuse 1 Open Buildservice 2024-11-21 4.6 MEDIUM 6.3 MEDIUM
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.
CVE-2014-5509 1 Clipboard Project 1 Clipboard 2024-11-21 3.6 LOW 5.5 MEDIUM
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
CVE-2014-4996 1 Vladtheenterprising Project 1 Vladtheenterprising 2024-11-21 2.1 LOW 5.5 MEDIUM
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
CVE-2014-4150 1 S48 1 Scheme48 2024-11-21 3.6 LOW 5.5 MEDIUM
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.
CVE-2014-3219 2 Fedoraproject, Fishshell 2 Fedora, Fish 2024-11-21 4.3 MEDIUM 7.8 HIGH
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
CVE-2014-2312 1 Intel 1 Thermald 2024-11-21 6.6 MEDIUM 5.5 MEDIUM
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
CVE-2014-1938 1 Rply Project 1 Rply 2024-11-21 2.1 LOW 5.5 MEDIUM
python-rply before 0.7.4 insecurely creates temporary files.
CVE-2014-1859 3 Fedoraproject, Numpy, Redhat 3 Fedora, Numpy, Enterprise Linux 2024-11-21 2.1 LOW 5.5 MEDIUM
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
CVE-2014-1420 1 Canonical 1 Ubuntu-ui-toolkit 2024-11-21 2.1 LOW 3.8 LOW
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink restrictions in Ubuntu. Fixed in 1.1.1188+14.10.20140813.4-0ubuntu1.
CVE-2014-0243 1 Check Mk Project 1 Check Mk 2024-11-21 2.1 LOW 5.5 MEDIUM
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
CVE-2013-4655 1 Belkin 2 N900, N900 Firmware 2024-11-21 7.8 HIGH 7.5 HIGH
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
CVE-2013-4364 1 Redhat 1 Openshift 2024-11-21 7.2 HIGH 7.8 HIGH
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
CVE-2013-4184 2 Data\, Debian 2 \, Debian Linux 2024-11-21 3.6 LOW 5.5 MEDIUM
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks