|
313321
|
7.0 |
HIGH
Local
|
symantec
|
antivirus_scan_engine
|
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUp…
|
CWE-59
Link Following
|
CVE-2004-0217
|
2024-01-27 02:21 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313322
|
5.5 |
MEDIUM
Local
|
mgetty_project
|
mgetty
|
faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.
|
CWE-59
Link Following
|
CVE-2003-0517
|
2024-01-27 02:20 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313323
|
7.8 |
HIGH
Local
|
ibm
|
u2_universe
|
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
|
CWE-59
Link Following
|
CVE-2003-0578
|
2024-01-27 02:19 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313324
|
7.8 |
HIGH
Local
|
oracle
|
mysql
|
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini ini…
|
CWE-120
Classic Buffer Overflow
|
CVE-2002-0969
|
2024-01-27 02:19 |
2002-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313325
|
5.5 |
MEDIUM
Local
|
blackberry
|
qnx_neutrino_real-time_operating_system
|
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d ar…
|
CWE-59
Link Following
|
CVE-2002-0793
|
2024-01-27 02:18 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313326
|
5.5 |
MEDIUM
Local
|
kernel avaya
|
util-linux cvlan interactive_response integrated_management_suit intuity_lx message_networking messaging_storage_server
|
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root ex…
|
CWE-59
Link Following
|
CVE-2001-1494
|
2024-01-27 02:16 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313327
|
7.1 |
HIGH
Local
|
microsoft
|
windows_nt
|
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock net…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2001-0006
|
2024-01-27 02:08 |
2001-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313328
|
4.7 |
MEDIUM
Local
|
gnu debian canonical
|
cpio debian_linux ubuntu_linux
|
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cp…
|
CWE-59 CWE-367
Link Following Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2005-1111
|
2024-01-27 02:07 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313329
|
5.5 |
MEDIUM
Local
|
gentoo
|
linux portage
|
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
|
CWE-59
Link Following
|
CVE-2004-1901
|
2024-01-27 02:07 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313330
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions …
|
CWE-59
Link Following
|
CVE-2004-1603
|
2024-01-27 02:06 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|