CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 1.2 | squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations. |
| 1mo ago | 1.2 | mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations. |
| 1mo ago | 1.2 | arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations. |
| 1mo ago | 1.2 | inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. |
| 1mo ago | 1.2 | privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 2.1 | The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs. |
| 1mo ago | 1.2 | Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 3.3 | htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 1.2 | exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file. |
| 1mo ago | 1.2 | useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 1.2 | getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 1.2 | rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 1.2 | sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack. |
| 1mo ago | 1.2 | gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 1.2 | rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file. |
| 1mo ago | 2.1 | The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files. |
| 1mo ago | 2.1 | Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. |
| 1mo ago | 2.1 | The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service. |
| 1mo ago | 2.1 | The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. |
| 1mo ago | 2.1 | Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit. |
| 1mo ago | 2.6 | A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability. |
| 1mo ago | 2.6 | The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability. |
| 1mo ago | 2.6 | Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability. |
| 1mo ago | 2.1 | IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. |
| 1mo ago | 2.1 | APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file. |
| 1mo ago | 1.2 | KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file. |
| 1mo ago | 1.2 | periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack. |
| 1mo ago | 2.1 | The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt). |
| 1mo ago | 2.1 | Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group. |
| 1mo ago | 1.2 | catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file. |