Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,606 CVEs tagged with CWE-5947 Critical, 709 High, 669 Medium, 180 Low, 1 Unrated.

CVE-2011-3616

Published Nov 4, 2011

The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3870

Published Oct 27, 2011

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3869

Published Oct 27, 2011

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4060

Published Oct 18, 2011

The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3204

Published Sep 6, 2011

hammerhead.cc in Hammerhead 2.1.4 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/hammer.log (aka the HH_LOG file) or (2) the REPORT_LOG file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0541

Published Sep 2, 2011

fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2185

Published Jul 27, 2011

Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a /tmp/fab.*.tar file or (2) certain other files in the top level of /tmp/.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5082

Published Jun 30, 2011

The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp fun…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5081

Published Jun 30, 2011

The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5080

Published Jun 30, 2011

The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not prope…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5079

Published Jun 30, 2011

The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files v…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5044

Published Jun 24, 2011

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2533

Published Jun 22, 2011

The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2473

Published Jun 9, 2011

The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in c…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1920

Published May 23, 2011

The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend####…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0012

Published Apr 18, 2011

The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, wh…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0461

Published Apr 4, 2011

/etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local users to overwrite arbitrary files…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0727

Published Mar 31, 2011

GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cac…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0441

Published Mar 29, 2011

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1073

Published Mar 4, 2011

crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1144

Published Mar 3, 2011

The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_di…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1072

Published Mar 3, 2011

The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1004

Published Mar 2, 2011

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1031

Published Feb 14, 2011

The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to create arbitrary files via a symlink attack on a /tmp/feh_ temporary file, a diffe…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0702

Published Feb 14, 2011

The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1,276-1,300 of 1,606 CVEsPage 52 of 65