Vulnerabilities (CVE)

Filtered by CWE-59
Total 1274 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-2312 1 Intel 1 Thermald 2024-11-21 6.6 MEDIUM 5.5 MEDIUM
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
CVE-2014-1938 1 Rply Project 1 Rply 2024-11-21 2.1 LOW 5.5 MEDIUM
python-rply before 0.7.4 insecurely creates temporary files.
CVE-2014-1859 3 Fedoraproject, Numpy, Redhat 3 Fedora, Numpy, Enterprise Linux 2024-11-21 2.1 LOW 5.5 MEDIUM
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
CVE-2014-0243 1 Check Mk Project 1 Check Mk 2024-11-21 2.1 LOW 5.5 MEDIUM
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
CVE-2013-4655 1 Belkin 2 N900, N900 Firmware 2024-11-21 7.8 HIGH 7.5 HIGH
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
CVE-2013-4364 1 Redhat 1 Openshift 2024-11-21 7.2 HIGH 7.8 HIGH
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
CVE-2013-4184 2 Data\, Debian 2 \, Debian Linux 2024-11-21 3.6 LOW 5.5 MEDIUM
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
CVE-2013-1867 1 Apple 2 Mac Os X, Tokend 2024-11-21 6.3 MEDIUM 6.1 MEDIUM
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
CVE-2013-1866 2 Apple, Opensc Project 2 Mac Os X, Opensc 2024-11-21 6.3 MEDIUM 6.1 MEDIUM
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
CVE-2013-1809 2 Debian, Gambas Project 2 Debian Linux, Gambas 2024-11-21 6.4 MEDIUM 7.5 HIGH
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
CVE-2013-1429 2 Canonical, Debian 3 Ubuntu Linux, Debian Linux, Lintian 2024-11-21 4.3 MEDIUM 6.3 MEDIUM
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
CVE-2013-0159 1 Fedoraproject 1 Fedora 2024-11-21 3.6 LOW 7.1 HIGH
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg.
CVE-2012-6114 1 Git-extras Project 1 Git-extras 2024-11-21 3.6 LOW 5.5 MEDIUM
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
CVE-2012-2945 1 Apache 1 Hadoop 2024-11-21 5.0 MEDIUM 7.5 HIGH
Hadoop 1.0.3 contains a symlink vulnerability.
CVE-2012-1093 1 Debian 2 Debian Linux, X11-common 2024-11-21 6.9 MEDIUM 7.8 HIGH
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
CVE-2011-5271 1 Clusterlabs 1 Pacemaker 2024-11-21 3.3 LOW 5.5 MEDIUM
Pacemaker before 1.1.6 configure script creates temporary files insecurely
CVE-2011-4116 1 Cpan 1 File\ 2024-11-21 5.0 MEDIUM 7.5 HIGH
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
CVE-2011-3632 3 Debian, Hardlink Project, Redhat 3 Debian Linux, Hardlink, Enterprise Linux 2024-11-21 3.6 LOW 7.1 HIGH
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
CVE-2011-3618 2 Atop Project, Debian 2 Atop, Debian Linux 2024-11-21 4.6 MEDIUM 7.8 HIGH
atop: symlink attack possible due to insecure tempfile handling
CVE-2011-3351 1 Openvas 1 Openvas-scanner 2024-11-21 6.6 MEDIUM 7.1 HIGH
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.