Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) — Vulnerability Class 418

418 vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2020-8013 permissions: chkstat sets unintended setuid/capabilities for mrsh and wodim — SUSE Linux Enterprise Server 12 2.2 Low2020-03-02
CVE-2019-18901 mysql-systemd-helper allows setting 640 permissions of arbitrary files — SUSE Linux Enterprise Server 12 5.1 Medium2020-03-02
CVE-2019-18897 Local privilege escalation from user salt to root — SUSE Linux Enterprise Server 12 8.4 High2020-03-02
CVE-2019-3698 nagios cron job allows privilege escalation from user nagios to root — SUSE Linux Enterprise Server 12 5.7 Medium2020-02-28
CVE-2020-8095 Bitdefender Total Security Link Resolution Denial-of-Service Vulnerability — Bitdefender Total Security 2020 4.9 Medium2020-01-30
CVE-2019-3699 Local privilege escalation from user privoxy to root — Leap 15.1 7.7 High2020-01-24
CVE-2019-3697 Local privilege escalation from user gnump3d to root — Leap 15.1 7.7 High2020-01-24
CVE-2019-3694 Local privilege escalation from munin to root in the packaging of munin — Factory 7.7 High2020-01-24
CVE-2019-3693 Local privilege escalation from user wwwrun to root in the packaging of mailman — SUSE Linux Enterprise Server 11 7.7 High2020-01-24
CVE-2019-3692 Local privilege escalation from user news to root in the packaging of inn — SUSE Linux Enterprise Server 11 7.7 High2020-01-24
CVE-2019-3691 Local privilege escalation from user munge to root — SUSE Linux Enterprise Server 15 7.7 High2020-01-23
CVE-2019-18898 trousers: Local privilege escalation from tss to root — SUSE Linux Enterprise Server 15 SP1 7.7 High2020-01-23
CVE-2019-8463 Check Point Endpoint Security Client 后置链接漏洞 — Check Point Endpoint Security Client for Windows 6.2 -2019-12-23
CVE-2019-18232 SafeNet Sentinel LDK License Manager 后置链接漏洞 — SafeNet Sentinel LDK License Manager Runtime 7.8 -2019-12-11
CVE-2019-3690 chkstat follows untrusted symbolic links — permissions 6.8 Medium2019-12-05
CVE-2019-12672 Cisco IOS XE Software Arbitrary Code Execution Vulnerability — Cisco IOS XE Software 3.11.1S 6.8 -2019-09-25
CVE-2019-10152 Podman 路径遍历漏洞 — podman 7.5 -2019-07-30
CVE-2018-14651 Red Hat Gluster 安全漏洞 — glusterfs 8.8 -2018-10-31
CVE-2018-10928 Red Hat glusterfs服务器RPC请求处理器组件后置链接漏洞 — glusterfs 8.8 -2018-09-04
CVE-2017-7500 Red Hat RPM 安全漏洞 — rpm 7.8 -2018-08-13
CVE-2018-10897 yum-utils 后置链接漏洞 — yum-utils: 7.5 -2018-08-01
CVE-2016-8641 Nagios 后置链接漏洞 — nagios 7.8 -2018-08-01
CVE-2017-15097 PostgreSQL 后置链接漏洞 — postgresql init script 7.2 -2018-07-27
CVE-2016-9602 QEMU 权限许可和访问控制漏洞 — Qemu 8.8 -2018-04-26
CVE-2018-1063 policycoreutils 后置链接漏洞 — policycoreutils 6.1 -2018-03-02
CVE-2017-7501 Red Hat RPM 安全漏洞 — rpm 7.8 -2017-11-22
CVE-2017-12172 PostgreSQL 安全漏洞 — postgresql 6.7 -2017-11-22
CVE-2017-12258 Cisco Unified Communications Manager 安全漏洞 — Cisco Unified Communications Manager 6.1 -2017-10-05

Vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) represent 418 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.