Vulnerability index

Browse CVEs

1,376 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Xml Dt MEDIUM 6.3
CVE-2014-5260

The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_#…

Fix: after 0.63
Fix from $1,600 2014-08-16
Linux Kernel MEDIUM 6.2
CVE-2014-5045

The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to …

Fix: 3.15.8+
Fix from $1,600 2014-08-01
Cloudforms 3.0 Management Engine MEDIUM 6.9
CVE-2014-3486

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
Vios MEDIUM 6.9
CVE-2014-3977

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this…

No fix yet
Fix from $1,600 2014-06-08
Pkstat MEDIUM 6.3
CVE-2013-0350

tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.

Mitigation only
Fix from $1,600 2014-05-05
Systemd MEDIUM 6.3
CVE-2012-0871

The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or…

Fix: after 037
Fix from $1,600 2014-04-18
Kbd MEDIUM 6.3
CVE-2011-0460

The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

Fix: after 1.14.1
Fix from $1,600 2014-04-16
Libvirt MEDIUM 5.8
CVE-2013-6456

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta…

Mitigation only
Fix from $1,600 2014-04-15
Tvos MEDIUM 6.3
CVE-2014-1272

CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by lever…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Cpio HIGH 7.2
CVE-2010-4226

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within…

Mitigation only
Fix from $1,950 2014-02-06
Enterprise Linux MEDIUM 6.3
CVE-2013-2561

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet…

No fix yet
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-2029

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arb…

Mitigation only
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-4214

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a sy…

Fix: after 3.5.1
Fix from $1,600 2013-11-23
Systemd MEDIUM 5.0
CVE-2013-4392

systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink…

Fix: 239+
Fix from $1,600 2013-10-28
Gnome Display Manager MEDIUM 6.9
CVE-2013-4169

GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.

Fix: after 2.21
Fix from $1,600 2013-09-10
Jboss Enterprise Web Server MEDIUM 6.9
CVE-2013-1976

The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0…

Mitigation only
Fix from $1,600 2013-07-09
Chrome Os HIGH 7.5
CVE-2013-0927

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the u…

Fix: after 26.0.1410.56
Fix from $1,950 2013-04-10
Support Tools MEDIUM 6.9
CVE-2013-1495

asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predic…

Fix: after 4.3.2
Fix from $1,600 2013-03-18
Fusionforge MEDIUM 6.9
CVE-2013-1423

(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-speci…

Mitigation only
Fix from $1,600 2013-03-14
Essex HIGH 8.8
CVE-2013-0261

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …

Mitigation only
Fix from $1,950 2013-03-08
Opencryptoki MEDIUM 6.2
CVE-2012-4455

openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptok…

Mitigation only
Fix from $1,600 2012-10-10
Monkey MEDIUM 6.9
CVE-2012-5303

Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname diffe…

Mitigation only
Fix from $1,600 2012-10-05
Enterprise Linux MEDIUM 5.6
CVE-2012-3440

A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on …

No fix yet
Fix from $1,600 2012-08-08
Ioquake3 Engine MEDIUM 5.6
CVE-2012-3345

ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.

Mitigation only
Fix from $1,600 2012-06-15
Conky MEDIUM 6.3
CVE-2011-3616

The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.…

Fix: after 1.8.1
Fix from $1,600 2011-11-04
Puppet MEDIUM 6.3
CVE-2011-3869

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

Patch available
Fix from $1,600 2011-10-27
Puppet MEDIUM 6.3
CVE-2011-3870

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on th…

Patch available
Fix from $1,600 2011-10-27
Oprofile MEDIUM 6.3
CVE-2011-2473

The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a craft…

Fix: after 0.9.6
Fix from $1,600 2011-06-09
Opensuse MEDIUM 6.3
CVE-2011-0461

/etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local user…

Mitigation only
Fix from $1,600 2011-04-04
Gdm MEDIUM 6.9
CVE-2011-0727

GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2)…

Patch available
Fix from $1,600 2011-03-31