Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,606 CVEs tagged with CWE-5946 Critical, 709 High, 667 Medium, 170 Low, 14 Unrated.

CVE-2008-4694

Published Oct 23, 2008

Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4639

Published Oct 21, 2008

jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4580

Published Oct 15, 2008

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4579

Published Oct 15, 2008

The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary f…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4553

Published Oct 15, 2008

qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and directories.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4477

Published Oct 8, 2008

alert.d/test.alert in mon 0.99.2 allows local users to overwrite arbitrary files via a symlink attack on the test.alert.log temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4476

Published Oct 7, 2008

sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, bu…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4475

Published Oct 7, 2008

ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4474

Published Oct 7, 2008

freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) mo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4440

Published Oct 3, 2008

The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/feta.avail.$USER temporary files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4406

Published Oct 3, 2008

A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attack on unspecified .tmp files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3521

Published Oct 2, 2008

Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4192

Published Sep 29, 2008

The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary f…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3524

Published Sep 29, 2008

rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1)…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4191

Published Sep 24, 2008

extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4190

Published Sep 24, 2008

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack o…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4162

Published Sep 22, 2008

Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the g_site_ur…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4108

Published Sep 18, 2008

Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4104

Published Sep 18, 2008

Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" U…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4085

Published Sep 15, 2008

plaiter in Plait before 1.6 allows local users to overwrite arbitrary files via a symlink attack on (1) cut.$$, (2) head.$$, (3) awk.$$, and (4) ps.$$ temporary files in /tmp/.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3946

Published Sep 5, 2008

The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3927

Published Sep 4, 2008

genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3928

Published Sep 4, 2008

test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3929

Published Sep 4, 2008

gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1,476-1,500 of 1,606 CVEsPage 60 of 65