Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,605 CVEs tagged with CWE-5946 Critical, 709 High, 668 Medium, 180 Low, 2 Unrated.

CVE-2011-0017

Published Feb 2, 2011

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3879

Published Jan 22, 2011

FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent d…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4338

Published Jan 20, 2011

ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR e…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4337

Published Jan 14, 2011

The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnin…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0402

Published Jan 11, 2011

dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0007

Published Jan 11, 2011

pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pim…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3847

Published Jan 7, 2011

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environmen…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4173

Published Nov 22, 2010

The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) ha…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1693

Published Oct 26, 2010

openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5007

Published Oct 14, 2010

The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3691

Published Oct 7, 2010

PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2794

Published Aug 30, 2010

The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2056

Published Jul 22, 2010

GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0832

Published Jul 12, 2010

pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local use…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2431

Published Jun 22, 2010

The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.ca…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2192

Published Jun 18, 2010

The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0546

Published Jun 17, 2010

Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2053

Published Jun 7, 2010

emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1626

Published May 21, 2010

MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a differe…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1160

Published Apr 16, 2010

GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite ar…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1183

Published Mar 29, 2010

Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0439

Published Mar 26, 2010

Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1299

Published Mar 18, 2010

The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack o…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0792

Published Mar 5, 2010

fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on an unspecified file.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 1,301-1,325 of 1,605 CVEsPage 53 of 65