Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,605 CVEs tagged with CWE-5946 Critical, 709 High, 668 Medium, 180 Low, 2 Unrated.

CVE-2009-0876

Published Mar 12, 2009

Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/set…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6398

Published Mar 4, 2009

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicaliz…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6397

Published Mar 4, 2009

rlatex in AlcoveBook sgml2x 1.0.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4284

Published Feb 10, 2009

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0356

Published Feb 4, 2009

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers t…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4990

Published Feb 2, 2009

Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/enomalism2.pid temporar…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0347

Published Jan 29, 2009

Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phish…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0321

Published Jan 28, 2009

Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0313

Published Jan 28, 2009

winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5825

Published Jan 2, 2009

The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5746

Published Dec 29, 2008

Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5743

Published Dec 26, 2008

pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup files with a predictable name, which allows local users to overwrite arbitrary files via a symlink attack.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5742

Published Dec 26, 2008

Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the red…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5706

Published Dec 22, 2008

The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a sym…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5704

Published Dec 22, 2008

src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporar…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5703

Published Dec 22, 2008

gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/gpsdrivepos temporary file, re…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5394

Published Dec 9, 2008

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack o…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5380

Published Dec 8, 2008

gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5379

Published Dec 8, 2008

netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-m…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5378

Published Dec 8, 2008

arb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary file.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5377

Published Dec 8, 2008

pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,351-1,375 of 1,605 CVEsPage 55 of 65