Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,657 CVEs tagged with CWE-5952 Critical, 733 High, 687 Medium, 185 Low, 0 Unrated.

CVE-2005-0587

Published Mar 25, 2005

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0967

Published Feb 9, 2005

The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, al…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2473

Published Dec 31, 2004

wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1603

Published Oct 18, 2004

cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Fr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0689

Published Sep 28, 2004

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1233

Published Dec 31, 2003

Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by usin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1492

Published Dec 31, 2003

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1528

Published Dec 31, 2003

nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0844

Published Nov 17, 2003

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0517

Published Aug 18, 2003

faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0578

Published Aug 18, 2003

cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary fil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2323

Published Dec 31, 2002

Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which coul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2374

Published Dec 31, 2002

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-2382

Published Dec 31, 2002

cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1378

Published Sep 6, 2001

fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1042

Published Jul 2, 2001

Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1043

Published Jul 1, 2001

ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1386

Published Jul 1, 2001

WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,626-1,650 of 1,657 CVEsPage 66 of 67