|
313491
|
7.8 |
HIGH
Local
|
ibm
|
u2_universe
|
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
|
CWE-59
Link Following
|
CVE-2003-0578
|
2024-01-27 02:19 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313492
|
7.8 |
HIGH
Local
|
oracle
|
mysql
|
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini ini…
|
CWE-120
Classic Buffer Overflow
|
CVE-2002-0969
|
2024-01-27 02:19 |
2002-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313493
|
5.5 |
MEDIUM
Local
|
blackberry
|
qnx_neutrino_real-time_operating_system
|
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d ar…
|
CWE-59
Link Following
|
CVE-2002-0793
|
2024-01-27 02:18 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313494
|
5.5 |
MEDIUM
Local
|
kernel avaya
|
util-linux cvlan interactive_response integrated_management_suit intuity_lx message_networking messaging_storage_server
|
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root ex…
|
CWE-59
Link Following
|
CVE-2001-1494
|
2024-01-27 02:16 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313495
|
7.1 |
HIGH
Local
|
microsoft
|
windows_nt
|
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock net…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2001-0006
|
2024-01-27 02:08 |
2001-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313496
|
4.7 |
MEDIUM
Local
|
gnu debian canonical
|
cpio debian_linux ubuntu_linux
|
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cp…
|
CWE-59 CWE-367
Link Following Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2005-1111
|
2024-01-27 02:07 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313497
|
5.5 |
MEDIUM
Local
|
gentoo
|
linux portage
|
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
|
CWE-59
Link Following
|
CVE-2004-1901
|
2024-01-27 02:07 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313498
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions …
|
CWE-59
Link Following
|
CVE-2004-1603
|
2024-01-27 02:06 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313499
|
7.1 |
HIGH
Local
|
kde debian
|
kde debian_linux
|
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
|
CWE-59
Link Following
|
CVE-2004-0689
|
2024-01-27 02:06 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313500
|
5.5 |
MEDIUM
Local
|
ekg_project debian
|
ekg debian_linux
|
linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
|
CWE-59
Link Following
|
CVE-2005-1916
|
2024-01-27 02:01 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|