Vulnerability index

Browse CVEs

1,376 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Ruby MEDIUM 6.3
CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1…

Patch available
Fix from $1,600 2011-03-02
Exim MEDIUM 6.9
CVE-2011-0017

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows loca…

Fix: after 4.72
Fix from $1,600 2011-02-02
Libfuse MEDIUM 5.8
CVE-2010-3879EPSS 10%

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a …

Fix: after 2.8.5
Fix from $1,600 2011-01-22
Ocrodjvu MEDIUM 6.2
CVE-2010-4338

ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cun…

Mitigation only
Fix from $1,600 2011-01-20
Dpkg MEDIUM 6.8
CVE-2011-0402

dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified fil…

Fix: after 1.14.30
Fix from $1,600 2011-01-11
Glibc MEDIUM 6.9
CVE-2010-3847EPSS 9%

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIG…

Fix: after 2.11.2
Fix from $1,600 2011-01-07
Enterprise Distribution MEDIUM 6.3
CVE-2010-1693

openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_n…

Mitigation only
Fix from $1,600 2010-10-26
Deliver MEDIUM 6.9
CVE-2010-0439

Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary…

Mitigation only
Fix from $1,600 2010-03-26
Pulseaudio MEDIUM 6.9
CVE-2009-1299

The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrar…

Mitigation only
Fix from $1,600 2010-03-18
MySQL MEDIUM 6.0
CVE-2008-7247

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to …

No fix yet
Fix from $1,600 2009-11-30
Postfix MEDIUM 6.9
CVE-2009-2939

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, …

No fix yet
Fix from $1,600 2009-09-21
Enterprise Linux MEDIUM 6.9
CVE-2009-1893

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar…

Mitigation only
Fix from $1,600 2009-07-17
Directadmin MEDIUM 6.9
CVE-2009-1526

JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temp…

Fix: 1.33.4+
Fix from $1,600 2009-05-05
Cluster Project MEDIUM 6.9
CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com…

Mitigation only
Fix from $1,600 2009-03-30
Xvm Virtualbox MEDIUM 6.9
CVE-2009-0876

Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink atta…

Patch available
Fix from $1,600 2009-03-12
Sng MEDIUM 6.9
CVE-2008-6398

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$…

No fix yet
Fix from $1,600 2009-03-04
Websphere Application Server MEDIUM 5.8
CVE-2008-4284

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x bef…

Patch available
Fix from $1,600 2009-02-10
Controllogix 1756 Enbt\/a Ethernet\/ Ip Bridge MEDIUM 6.8
CVE-2009-0473EPSS 13%

Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attacker…

Mitigation only
Fix from $1,600 2009-02-06
Firefox MEDIUM 5.1
CVE-2009-0356

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows us…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Sblim Sfcb MEDIUM 6.9
CVE-2009-0416

The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local us…

Mitigation only
Fix from $1,600 2009-02-03
Elastic Computing Platform MEDIUM 6.9
CVE-2008-4990

Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to overwrite arbitrary files via a symlink attack on th…

Fix: after 2.1
Fix from $1,600 2009-02-02
Ultraseek MEDIUM 5.8
CVE-2009-0347EPSS 11%

Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitra…

Mitigation only
Fix from $1,600 2009-01-29
Winetricks MEDIUM 6.9
CVE-2009-0313

winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.

Mitigation only
Fix from $1,600 2009-01-28
Cups MEDIUM 6.9
CVE-2009-0032

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrit…

Mitigation only
Fix from $1,600 2009-01-27
Windows 2000 HIGH 7.6
CVE-1999-1593EPSS 18%

Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch regist…

No fix yet
Fix from $1,950 2009-01-15
Snmp Management Agent MEDIUM 6.9
CVE-2008-5746

Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on …

Mitigation only
Fix from $1,600 2008-12-29
Pdfjam MEDIUM 6.9
CVE-2008-5743

pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup files with a predictable name, which allows local users to overwrite arbitrary files via a …

No fix yet
Fix from $1,600 2008-12-26
Gpsdrive MEDIUM 6.2
CVE-2008-5703

gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/…

Fix: after 2.10
Fix from $1,600 2008-12-22
Gpsdrive HIGH 7.6
CVE-2008-5704

src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gp…

Fix: after 2.10
Fix from $1,950 2008-12-22
Verlihub MEDIUM 6.9
CVE-2008-5706

The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overw…

No fix yet
Fix from $1,600 2008-12-22