Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,605 CVEs tagged with CWE-5946 Critical, 709 High, 668 Medium, 180 Low, 2 Unrated.

CVE-2010-0156

Published Mar 3, 2010

Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /t…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0789

Published Mar 2, 2010

fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0788

Published Mar 2, 2010

ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpum…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0787

Published Mar 2, 2010

client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain p…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0424

Published Feb 25, 2010

The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequen…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0118

Published Feb 25, 2010

Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4454

Published Dec 29, 2009

vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a symlink attack on /var/log/videocache/vccleaner.log.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3304

Published Dec 4, 2009

GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4193

Published Dec 3, 2009

Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4030

Published Nov 30, 2009

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7247

Published Nov 30, 2009

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1297

Published Oct 23, 2009

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitr…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1867

Published Jul 31, 2009

Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1893

Published Jul 17, 2009

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack o…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1962

Published Jun 8, 2009

Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pc…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1753

Published May 22, 2009

Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-1526

Published May 5, 2009

JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6762

Published Apr 28, 2009

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6760

Published Apr 28, 2009

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6759

Published Apr 28, 2009

ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1253

Published Apr 9, 2009

James Stone Tunapie 2.1 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,326-1,350 of 1,605 CVEsPage 54 of 65