CVE-2025-23394

CRITICAL Year: 2025
CVSS v3 Score
9.8
Critical

Vulnerability Description

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.

CVSS:9.8(Critical)

readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.

CWE-612024
CVSS:8.8(High)

An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete.

CWE-612024
CVSS:8.8(High)

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.

CWE-612024
CVSS:8.8(High)

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remedi...

CWE-612024
CVSS:8.1(High)

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of ...

CWE-612024
CVSS:9.8(Critical)

readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.

CWE-612024