Vulnerability index

Browse CVEs

1,376 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.3 CVE-2014-5260 The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_#… Xml Dt after 0.63 Fix from $1,6002014-08-16 MEDIUM 6.2 CVE-2014-5045 The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to … Linux Kernel 3.15.8+ Fix from $1,6002014-08-01 MEDIUM 6.9 CVE-2014-3486 The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme… Cloudforms 3.0 Management Engine after 5.2.4 Fix from $1,6002014-07-07 MEDIUM 6.9 CVE-2014-3977 libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this… Vios No fix yet Fix from $1,6002014-06-08 MEDIUM 6.3 CVE-2013-0350 tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log. Pkstat Mitigation only Fix from $1,6002014-05-05 MEDIUM 6.3 CVE-2012-0871 The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or… Systemd after 037 Fix from $1,6002014-04-18 MEDIUM 6.3 CVE-2011-0460 The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map. Kbd after 1.14.1 Fix from $1,6002014-04-16 MEDIUM 5.8 CVE-2013-6456 The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta… Libvirt Mitigation only Fix from $1,6002014-04-15 MEDIUM 6.3 CVE-2014-1272 CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by lever… Tvos after 7.0.6 Fix from $1,6002014-03-14 HIGH 7.2 CVE-2010-4226 cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within… Cpio Mitigation only Fix from $1,9502014-02-06 MEDIUM 6.3 CVE-2013-2561 OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet… Enterprise Linux No fix yet Fix from $1,6002013-11-23 MEDIUM 6.3 CVE-2013-2029 nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arb… Openstack Mitigation only Fix from $1,6002013-11-23 MEDIUM 6.3 CVE-2013-4214 rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a sy… Openstack after 3.5.1 Fix from $1,6002013-11-23 MEDIUM 5.0 CVE-2013-4392 systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink… Systemd 239+ Fix from $1,6002013-10-28 MEDIUM 6.9 CVE-2013-4169 GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/. Gnome Display Manager after 2.21 Fix from $1,6002013-09-10 MEDIUM 6.9 CVE-2013-1976 The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0… Jboss Enterprise Web Server Mitigation only Fix from $1,6002013-07-09 HIGH 7.5 CVE-2013-0927 Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the u… Chrome Os after 26.0.1410.56 Fix from $1,9502013-04-10 MEDIUM 6.9 CVE-2013-1495 asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predic… Support Tools after 4.3.2 Fix from $1,6002013-03-18 MEDIUM 6.9 CVE-2013-1423 (1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-speci… Fusionforge Mitigation only Fix from $1,6002013-03-14 HIGH 8.8 CVE-2013-0261 A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This … Essex Mitigation only Fix from $1,9502013-03-08 MEDIUM 6.2 CVE-2012-4455 openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptok… Opencryptoki Mitigation only Fix from $1,6002012-10-10 MEDIUM 6.9 CVE-2012-5303 Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname diffe… Monkey Mitigation only Fix from $1,6002012-10-05 MEDIUM 5.6 CVE-2012-3440 A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on … Enterprise Linux No fix yet Fix from $1,6002012-08-08 MEDIUM 5.6 CVE-2012-3345 ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file. Ioquake3 Engine Mitigation only Fix from $1,6002012-06-15 MEDIUM 6.3 CVE-2011-3616 The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.… Conky after 1.8.1 Fix from $1,6002011-11-04 MEDIUM 6.3 CVE-2011-3869 Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file. Puppet Patch available Fix from $1,6002011-10-27 MEDIUM 6.3 CVE-2011-3870 Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on th… Puppet Patch available Fix from $1,6002011-10-27 MEDIUM 6.3 CVE-2011-2473 The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a craft… Oprofile after 0.9.6 Fix from $1,6002011-06-09 MEDIUM 6.3 CVE-2011-0461 /etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local user… Opensuse Mitigation only Fix from $1,6002011-04-04 MEDIUM 6.9 CVE-2011-0727 GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2)… Gdm Patch available Fix from $1,6002011-03-31