CVE-2024-27885

CVSS v3 Score
6.3
Medium

Vulnerability Description

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, macOS Monterey 12.7.5. An app may be able to modify protected parts of the file system.

CVSS:6.3(Medium)

Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

CWE-592013
CVSS:6.3(Medium)

A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance ...

CWE-592020
CVSS:6.3(Medium)

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to re...

CWE-592020
CVSS:6.3(Medium)

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (pres...

CWE-592021
CVSS:6.3(Medium)

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in t...

CWE-592022
CVSS:6.3(Medium)

Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability

CWE-592023