| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo. |
| Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. |
| The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg. |
| General Electric D20ME devices are not properly configured and reveal plaintext passwords. |
| The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort. |
| ipa 3.0 does not properly check server identity before sending credential containing cookies |
| Claws Mail vCalendar plugin: credentials exposed on interface |
| Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. |
| Hadoop 1.0.3 contains a symlink vulnerability. |
| Moodle before 2.2.2 has users' private files included in course backups |
| The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation. |
| Pacemaker before 1.1.6 configure script creates temporary files insecurely |
| gpw generates shorter passwords than required |
| Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. |
| atop: symlink attack possible due to insecure tempfile handling |
| openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system. |
| foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. |
| foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. |
| pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks. |
| ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. |