Total
925 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-4406 | 1 Debian | 1 Xsabre | 2017-08-07 | 7.2 HIGH | N/A |
A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attack on unspecified .tmp files. | |||||
CVE-2008-4284 | 1 Ibm | 1 Websphere Application Server | 2017-08-07 | 5.8 MEDIUM | N/A |
Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature. | |||||
CVE-2008-4192 | 1 Redhat | 1 Cman | 2017-08-07 | 6.9 MEDIUM | N/A |
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file. | |||||
CVE-2008-4191 | 1 Emacspeak Inc | 1 Emacspeak | 2017-08-07 | 6.6 MEDIUM | N/A |
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file. | |||||
CVE-2008-4108 | 1 Python Software Foundation | 1 Python | 2017-08-07 | 7.2 HIGH | N/A |
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory. | |||||
CVE-2008-4085 | 1 Stephenjungels | 1 Plait | 2017-08-07 | 4.4 MEDIUM | N/A |
plaiter in Plait before 1.6 allows local users to overwrite arbitrary files via a symlink attack on (1) cut.$$, (2) head.$$, (3) awk.$$, and (4) ps.$$ temporary files in /tmp/. | |||||
CVE-2008-3946 | 1 Hp | 1 Openvms | 2017-08-07 | 4.9 MEDIUM | N/A |
The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file. | |||||
CVE-2008-3931 | 1 R Foundation | 1 R | 2017-08-07 | 6.9 MEDIUM | N/A |
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |||||
CVE-2008-3930 | 1 Debian | 1 Citadel Server | 2017-08-07 | 6.9 MEDIUM | N/A |
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||||
CVE-2008-3929 | 1 Ampache | 1 Ampache | 2017-08-07 | 7.2 HIGH | N/A |
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file. | |||||
CVE-2008-3928 | 1 Debian | 1 Honeyd Common | 2017-08-07 | 6.9 MEDIUM | N/A |
test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||||
CVE-2008-3927 | 1 Tiger | 1 Tiger | 2017-08-07 | 7.2 HIGH | N/A |
genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files. | |||||
CVE-2008-3883 | 1 Caudium | 1 Caudium | 2017-08-07 | 7.2 HIGH | N/A |
configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file. | |||||
CVE-2008-3699 | 1 Amarok | 1 Amarok | 2017-08-07 | 3.3 LOW | N/A |
The MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows local users to overwrite arbitrary files via a symlink attack on the album_info.xml temporary file. | |||||
CVE-2008-3216 | 1 Debian | 1 Projectl | 2017-08-07 | 4.6 MEDIUM | N/A |
The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, which allows local users to overwrite arbitrary files via a symlink attack. | |||||
CVE-2008-3227 | 1 Joomla | 1 Joomla | 2017-08-07 | 7.5 HIGH | N/A |
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability. | |||||
CVE-2008-3456 | 1 Phpmyadmin | 1 Phpmyadmin | 2017-08-07 | 6.4 MEDIUM | N/A |
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack. | |||||
CVE-2008-3524 | 1 Redhat | 2 Fedora, Initscripts | 2017-08-07 | 4.7 MEDIUM | N/A |
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run. | |||||
CVE-2008-3329 | 1 Twibright | 1 Links | 2017-08-07 | 9.3 HIGH | N/A |
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs." | |||||
CVE-2008-1417 | 1 Axyl | 1 Axyl | 2017-08-07 | 6.9 MEDIUM | N/A |
The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file. |