Vulnerability index

Browse CVEs

1,376 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Caudium HIGH 7.2
CVE-2008-3883

configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.

Mitigation only
Fix from $1,950 2008-09-02
phpMyAdmin MEDIUM 6.4
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for re…

Fix: after 2.11.7.0
Fix from $1,600 2008-08-04
Links HIGH 9.3
CVE-2008-3329

Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to ex…

Fix: after 2.1
Fix from $1,950 2008-07-27
Joomla HIGH 7.5
CVE-2008-3227

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redir…

Fix: after 1.5.3
Fix from $1,950 2008-07-18
Mac Os X HIGH 7.6
CVE-2008-2311

Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attac…

Patch available
Fix from $1,950 2008-07-01
Blender MEDIUM 6.9
CVE-2008-1103

Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."

No fix yet
Fix from $1,600 2008-04-28
Aptlinex HIGH 7.2
CVE-2008-1901

aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.

Mitigation only
Fix from $1,950 2008-04-22
Db2 Universal Database MEDIUM 6.9
CVE-2007-5664

db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 …

Patch available
Fix from $1,600 2008-04-16
Axyl MEDIUM 6.9
CVE-2008-1417

The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file.

Mitigation only
Fix from $1,600 2008-03-20
Xwine HIGH 7.2
CVE-2008-0930

w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire tempo…

Mitigation only
Fix from $1,950 2008-03-04
Linux HIGH 7.2
CVE-2008-1078

expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a syml…

No fix yet
Fix from $1,950 2008-02-29
Weblogic Portal HIGH 7.5
CVE-2008-0870

BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Ad…

Patch available
Fix from $1,950 2008-02-21
Xoops MEDIUM 5.0
CVE-2008-0613

Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing …

Patch available
Fix from $1,600 2008-02-06
Linux Kernel MEDIUM 6.9
CVE-2007-4998

cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symli…

Mitigation only
Fix from $1,600 2008-01-31
Gallery MEDIUM 6.4
CVE-2007-6692

Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

Fix: after 2.2.3
Fix from $1,600 2008-01-17
Audacity MEDIUM 5.0
CVE-2007-6061

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local us…

Patch available
Fix from $1,600 2007-11-20
Aix MEDIUM 6.9
CVE-2007-5805

cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to c…

Patch available
Fix from $1,600 2007-11-05
Sitebar MEDIUM 6.4
CVE-2007-5695

Open redirect vulnerability in command.php in SiteBar 3.3.8 allows remote attackers to redirect users to arbitrary web sites via a URL in the forward…

Patch available
Fix from $1,600 2007-10-29
Xen MEDIUM 6.0
CVE-2007-3919

(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.

Mitigation only
Fix from $1,600 2007-10-28
Etrust Integrated Threat Management MEDIUM 5.8
CVE-2007-5437

The web console in CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 allows remote attackers to redirect users to arbitrary web sites…

Mitigation only
Fix from $1,600 2007-10-13
Tramp MEDIUM 6.9
CVE-2007-5377

The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, a…

Mitigation only
Fix from $1,600 2007-10-12
Qgit MEDIUM 6.9
CVE-2007-4631

The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and e…

Patch available
Fix from $1,600 2007-08-31
Enterprise Linux MEDIUM 6.2
CVE-2007-3103

The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary fil…

Patch available
Fix from $1,600 2007-07-15
Eggblog MEDIUM 6.8
CVE-2007-2978

Session fixation vulnerability in eggblog 3.1.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: after 3.1.0
Fix from $1,600 2007-06-01
Mac Os X MEDIUM 6.8
CVE-2005-2714

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink …

Patch available
Fix from $1,600 2005-12-31
Debian Linux MEDIUM 5.5
CVE-2005-1916

linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

Fix: after 2005-06-05
Fix from $1,600 2005-07-06
Lutelwall MEDIUM 5.5
CVE-2005-1879

LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.

Fix: 0.98+
Fix from $1,600 2005-06-09
Everybuddy MEDIUM 5.5
CVE-2005-1880

everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wge…

Fix: after 0.4.3
Fix from $1,600 2005-06-06
Mathopd MEDIUM 5.5
CVE-2005-0824

The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to ove…

Fix: 1.5+
Fix from $1,600 2005-05-02
Firefox MEDIUM 6.5
CVE-2005-0587

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a …

Fix: 1.0.1 / 1.7.6+
Fix from $1,600 2005-03-25