Search Results (7925 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-32931 2024-08-06 5.7 Medium
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
CVE-2012-4510 1 Cups-pk-helper Project 1 Cups-pk-helper 2024-08-06 N/A
cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.
CVE-2012-4455 1 Opencryptoki Project 1 Opencryptoki 2024-08-06 N/A
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.
CVE-2012-3823 1 Arialsoftware 1 Campaign Enterprise 2024-08-06 7.5 High
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
CVE-2012-3440 2 Redhat, Todd Miller 2 Enterprise Linux, Sudo 2024-08-06 N/A
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
CVE-2012-3329 2 Ibm, Linux 3 Advanced Settings Utility, Bootable Media Creator, Linux Kernel 2024-08-06 N/A
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.
CVE-2012-2945 1 Apache 1 Hadoop 2024-08-06 7.5 High
Hadoop 1.0.3 contains a symlink vulnerability.
CVE-2012-2103 1 Munin-monitoring 1 Munin 2024-08-06 N/A
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
CVE-2024-4699 2024-08-06 6.3 Medium
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-263747. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CVE-2012-1156 3 Fedoraproject, Moodle, Redhat 3 Fedora, Moodle, Enterprise Linux 2024-08-06 7.5 High
Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-1093 1 Debian 2 Debian Linux, X11-common 2024-08-06 7.8 High
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
CVE-2012-0871 2 Opensuse, Systemd Project 2 Opensuse, Systemd 2024-08-06 N/A
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
CVE-2012-0911 1 Tiki 1 Tikiwiki Cms\/groupware 2024-08-06 9.8 Critical
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.
CVE-2012-0808 1 Bdale Garbee 1 As31 2024-08-06 N/A
as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack.
CVE-2024-40464 1 Beego 1 Beego 2024-08-06 8.8 High
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file
CVE-2012-0054 1 Golismero 1 Golismero 2024-08-06 N/A
libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.
CVE-2013-7489 1 Beakerbrowser 1 Beaker 2024-08-06 6.8 Medium
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
CVE-2013-7393 1 Apache 1 Subversion 2024-08-06 N/A
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
CVE-2013-7052 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-08-06 9.8 Critical
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
CVE-2013-7055 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-08-06 9.8 Critical
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure