Vulnerability index

Browse CVEs

1,376 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.3 CVE-2011-1004 The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1… Ruby Patch available Fix from $1,6002011-03-02 MEDIUM 6.9 CVE-2011-0017 The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows loca… Exim after 4.72 Fix from $1,6002011-02-02 MEDIUM 5.8 CVE-2010-3879EPSS 10% FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a … Libfuse after 2.8.5 Fix from $1,6002011-01-22 MEDIUM 6.2 CVE-2010-4338 ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cun… Ocrodjvu Mitigation only Fix from $1,6002011-01-20 MEDIUM 6.8 CVE-2011-0402 dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified fil… Dpkg after 1.14.30 Fix from $1,6002011-01-11 MEDIUM 6.9 CVE-2010-3847EPSS 9% elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIG… Glibc after 2.11.2 Fix from $1,6002011-01-07 MEDIUM 6.3 CVE-2010-1693 openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_n… Enterprise Distribution Mitigation only Fix from $1,6002010-10-26 MEDIUM 6.9 CVE-2010-0439 Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary… Deliver Mitigation only Fix from $1,6002010-03-26 MEDIUM 6.9 CVE-2009-1299 The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrar… Pulseaudio Mitigation only Fix from $1,6002010-03-18 MEDIUM 6.0 CVE-2008-7247 sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to … MySQL No fix yet Fix from $1,6002009-11-30 MEDIUM 6.9 CVE-2009-2939 The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, … Postfix No fix yet Fix from $1,6002009-09-21 MEDIUM 6.9 CVE-2009-1893 The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar… Enterprise Linux Mitigation only Fix from $1,6002009-07-17 MEDIUM 6.9 CVE-2009-1526 JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temp… Directadmin 1.33.4+ Fix from $1,6002009-05-05 MEDIUM 6.9 CVE-2008-6552 Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com… Cluster Project Mitigation only Fix from $1,6002009-03-30 MEDIUM 6.9 CVE-2009-0876 Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink atta… Xvm Virtualbox Patch available Fix from $1,6002009-03-12 MEDIUM 6.9 CVE-2008-6398 sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$… Sng No fix yet Fix from $1,6002009-03-04 MEDIUM 5.8 CVE-2008-4284 Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x bef… Websphere Application Server Patch available Fix from $1,6002009-02-10 MEDIUM 6.8 CVE-2009-0473EPSS 13% Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attacker… Controllogix 1756 Enbt\/a Ethernet\/ Ip Bridge Mitigation only Fix from $1,6002009-02-06 MEDIUM 5.1 CVE-2009-0356 Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows us… Firefox after 3.0.5 Fix from $1,6002009-02-04 MEDIUM 6.9 CVE-2009-0416 The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local us… Sblim Sfcb Mitigation only Fix from $1,6002009-02-03 MEDIUM 6.9 CVE-2008-4990 Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to overwrite arbitrary files via a symlink attack on th… Elastic Computing Platform after 2.1 Fix from $1,6002009-02-02 MEDIUM 5.8 CVE-2009-0347EPSS 11% Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitra… Ultraseek Mitigation only Fix from $1,6002009-01-29 MEDIUM 6.9 CVE-2009-0313 winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file. Winetricks Mitigation only Fix from $1,6002009-01-28 MEDIUM 6.9 CVE-2009-0032 CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrit… Cups Mitigation only Fix from $1,6002009-01-27 HIGH 7.6 CVE-1999-1593EPSS 18% Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch regist… Windows 2000 No fix yet Fix from $1,9502009-01-15 MEDIUM 6.9 CVE-2008-5746 Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on … Snmp Management Agent Mitigation only Fix from $1,6002008-12-29 MEDIUM 6.9 CVE-2008-5743 pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup files with a predictable name, which allows local users to overwrite arbitrary files via a … Pdfjam No fix yet Fix from $1,6002008-12-26 MEDIUM 6.2 CVE-2008-5703 gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/… Gpsdrive after 2.10 Fix from $1,6002008-12-22 HIGH 7.6 CVE-2008-5704 src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gp… Gpsdrive after 2.10 Fix from $1,9502008-12-22 MEDIUM 6.9 CVE-2008-5706 The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overw… Verlihub No fix yet Fix from $1,6002008-12-22