Vulnerability index

Browse CVEs

50 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Debian Linux MEDIUM 5.5
CVE-2017-16611

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, w…

Fix: 1.5.4 / 2.0.3+
Fix from $1,600 2017-12-01
Debian Linux HIGH 7.5
CVE-2017-1000115

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

Fix: 4.3+
Fix from $1,950 2017-10-05
Debian Linux MEDIUM 6.7
CVE-2017-9525

In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to…

Fix: after 3.0pl1-128.
Fix from $1,600 2017-06-09
Debian Linux HIGH 7.8
CVE-2016-9774

The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 1…

Mitigation only
Fix from $1,950 2017-03-23
Dpkg MEDIUM 6.8
CVE-2011-0402

dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified fil…

Fix: after 1.14.30
Fix from $1,600 2011-01-11
Shadow HIGH 7.2
CVE-2008-5394

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrar…

No fix yet
Fix from $1,950 2008-12-09
Mailscanner MEDIUM 6.9
CVE-2008-5140

trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack …

Mitigation only
Fix from $1,600 2008-11-18
Ltp MEDIUM 6.9
CVE-2008-5145

ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.

Mitigation only
Fix from $1,600 2008-11-18
Os Prober MEDIUM 6.2
CVE-2008-5135

os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map t…

Mitigation only
Fix from $1,600 2008-11-18
Initramfs Tools MEDIUM 5.5
CVE-2008-4996

init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE:…

No fix yet
Fix from $1,600 2008-11-07
Newsgate MEDIUM 6.9
CVE-2008-4975

mkmailpost in newsgate 1.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mmp##### temporary file.

No fix yet
Fix from $1,600 2008-11-06
Myspell MEDIUM 6.9
CVE-2008-4973

i2myspell in myspell 3.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/i2my#####.1 and (2) /tmp/i2my#####.2 tempor…

No fix yet
Fix from $1,600 2008-11-06
Dpkg Cross MEDIUM 6.9
CVE-2008-4950

gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the v…

No fix yet
Fix from $1,600 2008-11-05
Feta HIGH 7.2
CVE-2008-4440

The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/fe…

Mitigation only
Fix from $1,950 2008-10-03
Xsabre HIGH 7.2
CVE-2008-4406

A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attac…

Mitigation only
Fix from $1,950 2008-10-03
Honeyd Common MEDIUM 6.9
CVE-2008-3928

test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.

Mitigation only
Fix from $1,600 2008-09-04
Citadel Server MEDIUM 6.9
CVE-2008-3930

migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Mitigation only
Fix from $1,600 2008-09-04
Aptlinex HIGH 7.2
CVE-2008-1901

aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.

Mitigation only
Fix from $1,950 2008-04-22
Debian Linux MEDIUM 5.5
CVE-2005-1916

linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

Fix: after 2005-06-05
Fix from $1,600 2005-07-06
Debian Linux HIGH 7.1
CVE-2004-0689

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate…

Fix: 3.3+
Fix from $1,950 2004-09-28