Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,606 CVEs tagged with CWE-5946 Critical, 709 High, 667 Medium, 170 Low, 14 Unrated.

CVE-2008-3930

Published Sep 4, 2008

migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3931

Published Sep 4, 2008

javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3791

Published Sep 3, 2008

src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary f…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3883

Published Sep 2, 2008

configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3699

Published Aug 14, 2008

The MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows local users to overwrite arbitrary files via a symlink…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3456

Published Aug 4, 2008

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoo…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3329

Published Jul 27, 2008

Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3261

Published Jul 22, 2008

Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3216

Published Jul 18, 2008

The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, which allows local users to overwrite arbitrary files via a s…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3227

Published Jul 18, 2008

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2389

Published Jun 6, 2008

opensuse-updater in openSUSE 10.2 allows local users to access arbitrary files via a symlink attack.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0167

Published May 18, 2008

The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attac…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2266

Published May 16, 2008

uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1103

Published Apr 28, 2008

Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1694

Published Apr 22, 2008

vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1901

Published Apr 22, 2008

aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5664

Published Apr 16, 2008

db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1832

Published Apr 16, 2008

lib/prefs.tcl in Cecilia 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the csvers temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1684

Published Apr 6, 2008

inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1241

Published Mar 27, 2008

GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XU…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1417

Published Mar 20, 2008

The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1199

Published Mar 6, 2008

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other us…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,501-1,525 of 1,606 CVEsPage 61 of 65