Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,657 CVEs tagged with CWE-5952 Critical, 733 High, 687 Medium, 185 Low, 0 Unrated.

CVE-2009-5023

Published Jun 10, 2014

The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbit…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3977

Published Jun 8, 2014

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3986

Published Jun 8, 2014

include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3982

Published Jun 8, 2014

include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3981

Published Jun 8, 2014

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1934

Published May 8, 2014

tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3424

Published May 8, 2014

lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3423

Published May 8, 2014

lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3422

Published May 8, 2014

lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3421

Published May 8, 2014

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4215

Published May 5, 2014

The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a symlink attack on /tmp/ipxping/ipxping.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0350

Published May 5, 2014

tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5105

Published Apr 27, 2014

The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file.…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2893

Published Apr 23, 2014

The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4472

Published Apr 22, 2014

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a s…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2105

Published Apr 22, 2014

The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0871

Published Apr 18, 2014

The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0460

Published Apr 16, 2014

The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6456

Published Apr 15, 2014

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1593

Published Apr 5, 2014

The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary file…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1272

Published Mar 14, 2014

CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1838

Published Mar 11, 2014

The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other uns…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,251-1,275 of 1,657 CVEsPage 51 of 67