Vulnerability index

Browse CVEs

1,376 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Ghostscript HIGH 7.2
CVE-2004-0967

The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, a…

Patch available
Fix from $1,950 2005-02-09
Linux MEDIUM 5.5
CVE-2004-1901

Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.

Fix: 2.0.50+
Fix from $1,600 2004-12-31
Cpanel MEDIUM 5.5
CVE-2004-1603

cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files …

Patch available
Fix from $1,600 2004-10-18
Debian Linux HIGH 7.1
CVE-2004-0689

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate…

Fix: 3.3+
Fix from $1,950 2004-09-28
Antivirus Scan Engine HIGH 7.0
CVE-2004-0217

The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to a…

Patch available
Fix from $1,950 2004-04-15
Integrity Protection Driver CRITICAL 9.8
CVE-2003-1233

Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions…

Fix: after 1.3
Fix from $2,300 2003-12-31
Firefox MEDIUM 5.0
CVE-2003-1492

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with…

No fix yet
Fix from $1,600 2003-12-31
Siemens Networker HIGH 7.2
CVE-2003-1528

nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

No fix yet
Fix from $1,950 2003-12-31
Mod Gzip HIGH 7.1
CVE-2003-0844

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwr…

Fix: after 1.3.26.1a
Fix from $1,950 2003-11-17
Mgetty MEDIUM 5.5
CVE-2003-0517

faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.

Fix: after 1.1.28
Fix from $1,600 2003-08-18
U2 Universe HIGH 7.8
CVE-2003-0578

cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting…

Fix: after 10.0.0.9
Fix from $1,950 2003-08-18
Solaris Pc Netlink HIGH 7.5
CVE-2002-2323

Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been re…

Fix: after 1.2
Fix from $1,950 2002-12-31
Patchpro HIGH 10.0
CVE-2002-2374

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

Patch available
Fix from $1,950 2002-12-31
Cvsup HIGH 7.2
CVE-2002-2382

cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.

Patch available
Fix from $1,950 2002-12-31
Windows 2000 MEDIUM 5.5
CVE-2002-0725

NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, whic…

Mitigation only
Fix from $1,600 2002-09-05
Qnx Neutrino Real Time Operating System MEDIUM 5.5
CVE-2002-0793

Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the…

Patch available
Fix from $1,600 2002-08-12
Point To Point Protocol Daemon MEDIUM 6.9
CVE-2002-0824

BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.

Mitigation only
Fix from $1,600 2002-08-12
Util Linux MEDIUM 5.5
CVE-2001-1494

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log f…

Fix: 2.11n+
Fix from $1,600 2001-12-31
Broker Ftp Server HIGH 7.5
CVE-2001-1042

Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target fi…

No fix yet
Fix from $1,950 2001-07-02
Ftp Server HIGH 7.5
CVE-2001-1043

ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target…

No fix yet
Fix from $1,950 2001-07-01
Wftpd HIGH 7.5
CVE-2001-1386

WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check …

Patch available
Fix from $1,950 2001-07-01
Joe MEDIUM 5.5
CVE-2000-1178

Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the …

Patch available
Fix from $1,600 2001-01-09
Hp Ux MEDIUM 5.5
CVE-2000-0972

HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session,…

No fix yet
Fix from $1,600 2000-12-19
Eudora HIGH 7.5
CVE-2000-0342

Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refer…

No fix yet
Fix from $1,950 2000-04-28
Perl MEDIUM 5.5
CVE-1999-1386

Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink…

Fix: after 5.004_04
Fix from $1,600 1999-12-31
FreeBSD MEDIUM 5.5
CVE-1999-0783

FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.

Mitigation only
Fix from $1,600 1998-06-16