|
314621
|
5.5 |
MEDIUM
Local
|
blackberry
|
qnx_neutrino_real-time_operating_system
|
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d ar…
|
CWE-59
Link Following
|
CVE-2002-0793
|
2024-01-27 02:18 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314622
|
5.5 |
MEDIUM
Local
|
kernel avaya
|
util-linux cvlan interactive_response integrated_management_suit intuity_lx message_networking messaging_storage_server
|
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root ex…
|
CWE-59
Link Following
|
CVE-2001-1494
|
2024-01-27 02:16 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314623
|
7.1 |
HIGH
Local
|
microsoft
|
windows_nt
|
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock net…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2001-0006
|
2024-01-27 02:08 |
2001-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314624
|
4.7 |
MEDIUM
Local
|
gnu debian canonical
|
cpio debian_linux ubuntu_linux
|
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cp…
|
CWE-59 CWE-367
Link Following Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2005-1111
|
2024-01-27 02:07 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314625
|
5.5 |
MEDIUM
Local
|
gentoo
|
linux portage
|
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
|
CWE-59
Link Following
|
CVE-2004-1901
|
2024-01-27 02:07 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314626
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions …
|
CWE-59
Link Following
|
CVE-2004-1603
|
2024-01-27 02:06 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314627
|
7.1 |
HIGH
Local
|
kde debian
|
kde debian_linux
|
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
|
CWE-59
Link Following
|
CVE-2004-0689
|
2024-01-27 02:06 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314628
|
5.5 |
MEDIUM
Local
|
ekg_project debian
|
ekg debian_linux
|
linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
|
CWE-59
Link Following
|
CVE-2005-1916
|
2024-01-27 02:01 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314629
|
5.5 |
MEDIUM
Local
|
lutel
|
lutelwall
|
LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
|
CWE-59
Link Following
|
CVE-2005-1879
|
2024-01-27 02:01 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314630
|
5.5 |
MEDIUM
Local
|
everybuddy
|
everybuddy
|
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
|
CWE-59
Link Following
|
CVE-2005-1880
|
2024-01-27 02:00 |
2005-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|