Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel.
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traef
astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink
A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of
Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file
readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a
An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated p
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulne
Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow
An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from th
Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an atta
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prio
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability.
Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attac
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability.
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability.
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be abl
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.6. An app may be a
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Ac
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove
Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted contai
runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as w
Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure h
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unifie
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' esca
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 c
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unkno
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 a
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the n
Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Man
A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbi
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
Frequently Asked Questions
What is CWE-61?
CWE-61 (CWE-61) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-61?
There are 168 CVE records associated with CWE-61 in our database. Of these, 12 are critical severity, 70 are high severity, and 66 are medium severity.
How can I protect against CWE-61 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-61 using AI-powered security agents.
Detect CWE-61 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-61 vulnerabilities across your infrastructure.
Get Started