Threats Tagged 'cwe-61'
View all threats tagged with 'cwe-61'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-61'
Click on any threat for detailed analysis and mitigation recommendations
0 HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. Join the discussion | CVE Database V5 | 09/16/2026, 18:45:51 UTC Added: 09/16/2026, 19:02:17 UTC |
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 03:52:44 UTC |
0 Dell PowerProtect Cyber Recovery versions prior to 20.3 contain a UNIX Symbolic Link (Symlink) Following vulnerability (CWE-61). This flaw allows a low privileged local attacker to potentially perform script injection. The vulnerability has a medium severity with a CVSS score of 5.8. No official patch or remediation guidance has been provided yet by the vendor. Join the discussion | CVE Database V5 | 08/26/2026, 19:32:57 UTC Added: 08/26/2026, 20:07:55 UTC |
0 CVE-2026-75038 is a vulnerability in the ilya-zlobintsev LACT software up to version 0.10.0 that involves unsafe following of UNIX symbolic links (symlinks). This flaw can be exploited locally to cause a denial-of-service condition. The vulnerability does not impact confidentiality but can affect integrity and availability. No official patch or fix information is provided in the available data. Join the discussion | CVE Database V5 | 08/25/2026, 10:00:47 UTC Added: 08/25/2026, 10:08:03 UTC |
0 Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the instance's backup file, it follows the symlink. Version 7.3.0 patches the issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:49:16 UTC Added: 08/21/2026, 15:08:24 UTC |
Bulletin ID: 2026-003-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/01/23 12:30 PM PST Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. Firecracker runs in user space and uses the Linux Kernel-based Virtual Machine (KVM) to create microVMs. Each Firecracker microVM is further isolated with common Linux user-space security barriers by a companion program called "jailer". The jailer provides a second line of defense in case a user escapes from the microVM boundaries and it is released at each Firecracker version. We are aware of CVE-2026-1386, an issue that is related to the Firecracker jailer, which under certain circumstances can allow an user to overwrite arbitrary files in the host filesystem. AWS services that use Firecracker are not impacted by the issue as we appropriately restrict access to the host and the jailer folder, blocking the preconditions required for the attack to happen. Impacted versions: Firecracker version v1.13.1 and earlier and 1.14.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:57 UTC Added: 01/23/2026, 20:35:58 UTC |
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0. Join the discussion | CVE Database V5 | 08/20/2026, 16:18:06 UTC Added: 08/20/2026, 16:38:18 UTC |
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. Join the discussion | CVE Database V5 | 08/18/2026, 17:50:21 UTC Added: 08/18/2026, 18:04:53 UTC |
crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named `ptmx` in the target directory was also replaced by crun's forced `ptmx -> pts/ptmx` symlink. Version 1.28 fixes the issue. Join the discussion | CVE Database V5 | 08/14/2026, 16:16:37 UTC Added: 08/14/2026, 16:27:44 UTC |
aiohttp's static file serving mechanism has a vulnerability where symbolic links to compressed file variants (.gz or .br) are followed without proper path traversal checks. This can allow access to files outside the intended root directory if such symbolic links exist or can be created. The issue arises because the server does not perform path traversal validation on these compressed variants when serving files. This vulnerability affects servers that serve static routes containing such symbolic links and could be exploited to read unintended files. Join the discussion | CVE Database V5 | 08/13/2026, 16:44:03 UTC Added: 06/09/2025, 12:22:43 UTC |
Showing 1 to 10 of 70 results