Total
925 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-1526 | 1 Jbmc-software | 1 Directadmin | 2010-03-28 | 6.9 MEDIUM | N/A |
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action. | |||||
CVE-2009-3304 | 1 Gforge | 1 Gforge | 2009-12-06 | 3.3 LOW | N/A |
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php. | |||||
CVE-2008-4979 | 1 Shrubbery | 1 Rancid | 2009-09-14 | 6.9 MEDIUM | N/A |
getipacctg in rancid 2.3.2~a8 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/ipacct.#####.prefixes, (2) /tmp/ipacct.#####.sorted, (3) /tmp/ipacct.#####.pl, and (4) /tmp/ipacct.##### temporary files. | |||||
CVE-2008-4980 | 1 Zak B Elep | 1 Rccp | 2009-09-14 | 6.9 MEDIUM | N/A |
delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file. | |||||
CVE-2008-4975 | 1 Debian | 1 Newsgate | 2009-09-14 | 6.9 MEDIUM | N/A |
mkmailpost in newsgate 1.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mmp##### temporary file. | |||||
CVE-2008-5371 | 1 Marc Gloor | 1 Screenie | 2009-09-10 | 6.9 MEDIUM | N/A |
screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file. | |||||
CVE-2008-5375 | 1 Cmus | 1 Cmus | 2009-09-10 | 6.9 MEDIUM | N/A |
cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file. | |||||
CVE-2008-4954 | 1 Fumitoshi Ukai | 1 Fml | 2009-08-25 | 6.9 MEDIUM | N/A |
mead.pl in fml 4.0.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/debugbuf temporary file. | |||||
CVE-2008-4948 | 1 Nostatic | 1 Digitaldj | 2009-08-25 | 6.9 MEDIUM | N/A |
fest.pl in digitaldj 0.7.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ddj_fest.tmp temporary file. | |||||
CVE-2008-4960 | 1 Dov Grobgeld | 1 Impose\+ | 2009-08-25 | 6.9 MEDIUM | N/A |
impose in impose+ 0.2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-tmp.ps and (2) /tmp/bboxx-* temporary files. | |||||
CVE-2008-4947 | 1 Guus Sliepen | 1 Dhis-server | 2009-08-25 | 6.9 MEDIUM | N/A |
dhis-dummy-log-engine in dhis-server 5.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/dhis-dummy-log-engine.log temporary file. | |||||
CVE-2008-5703 | 1 Gpsdrive | 1 Gpsdrive | 2009-08-18 | 6.2 MEDIUM | N/A |
gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/gpsdrivepos temporary file, related to (1) examples/gpssmswatch and (2) src/splash.c, different vectors than CVE-2008-4959 and CVE-2008-5380. | |||||
CVE-2008-5380 | 1 Gpsdrive | 1 Gpsdrive | 2009-08-18 | 6.9 MEDIUM | N/A |
gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, related to the (1) geo-code and (2) geo-nearest scripts, different vectors than CVE-2008-4959. | |||||
CVE-2008-4943 | 1 Iglues | 1 Bulmages-servers | 2009-07-20 | 6.9 MEDIUM | N/A |
bulmages-servers 0.11.1 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/error.txt, (b) /tmp/errores.txt, and possibly other temporary files, related to the (1) creabulmafact, (2) creabulmacont, and possibly (3) actualizabulmacont, (4) installbulmages-db, and (5) actualizabulmafact scripts. | |||||
CVE-2008-4956 | 1 Firewallbuilder | 1 Fwbuilder | 2009-07-19 | 6.9 MEDIUM | N/A |
fwb_install in fwbuilder 2.1.19 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/ssh-agent.##### temporary file. | |||||
CVE-2008-4953 | 1 Firehol | 1 Firehol | 2009-07-19 | 6.9 MEDIUM | N/A |
** DISPUTED ** firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks." | |||||
CVE-2008-4950 | 1 Debian | 1 Dpkg-cross | 2009-07-19 | 6.9 MEDIUM | N/A |
** DISPUTED ** gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that "There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot." | |||||
CVE-2008-4946 | 1 Convirture | 1 Convirt | 2009-07-19 | 6.9 MEDIUM | N/A |
convirt 0.8.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/set_output temporary file, related to the (1) _template_/provision.sh, (2) Linux_CD_Install/provision.sh, (3) Fedora_PV_Install/provision.sh, (4) CentOS_PV_Install/provision.sh, (5) common/provision.sh, (6) example/provision.sh, and (7) Windows_CD_Install/provision.sh scripts in image_store/. | |||||
CVE-2008-4955 | 1 Duncan Webb | 1 Freevo | 2009-07-19 | 6.2 MEDIUM | N/A |
freevo.real in freevo 1.8.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-#####.pid, (2) /tmp/freevo-gdb, (3) /tmp/freevo-gdb.sh, and (4) /tmp/*.stats temporary files. NOTE: this issue is only a vulnerability when a verbose debug mode is activated by modifying source code. | |||||
CVE-2008-5378 | 1 Lehrstuhl Fur Mikrobiologie | 1 Arb | 2009-07-14 | 6.9 MEDIUM | N/A |
arb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary file. |