VulnSea

CWE-59

CVEs classified under CWE-59, newest first.

219 CVEsRSS

CVE-2020-23968High· 7.8PoC
5y ago

Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.

Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.

▾ Midnightilex · international_sign&goEPSS 0.90%via NVD
CVE-2020-0787High· 7.8CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

▾ Abyssalmicrosoft · windows_10_1507EPSS 43%via NVD
CVE-2020-0638High· 7.8CISA KEV
6y ago

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager …

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager …

▾ Abyssalmicrosoft · windows_10_1709EPSS 2.4%via NVD
CVE-2011-1136Medium· 4.7
6y ago

In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

▾ Sunlittesseract-ocr · tesseract_ocrEPSS 0.46%via NVD
CVE-2019-1385High· 7.8CISA KEV0day
6y ago

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need …

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need …

▾ Abyssalmicrosoft · windows_10_1709EPSS 3.6%via NVD
CVE-2019-1130High· 7.8CISA KEV0day
7y ago

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

▾ Abyssalmicrosoft · windows_10_1507EPSS 1.7%via NVD
CVE-2019-1069High· 7.8CISA KEVPoC
7y ago

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploi…

▾ Abyssalmicrosoft · windows_10_1507EPSS 6.1%via NVD
CVE-2015-5287High· 7.8CISA KEVPoC
10y ago

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

▾ Abyssalredhat · automatic_bug_reporting_toolEPSS 5.0%via NVD
CVE-2014-6407High· 7.5
11y ago

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

▾ Twilightdocker · dockerEPSS 4.9%via NVD
CWE-59 vulnerabilities (CVEs) — page 8 · VulnSea