Vulnerabilities (CVE)

Filtered by CWE-59
Total 1127 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4098 4 Canonical, Debian, Mysql and 1 more 4 Ubuntu Linux, Debian Linux, Mysql and 1 more 2019-12-17 4.6 MEDIUM N/A
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
CVE-2008-7247 2 Mysql, Oracle 2 Mysql, Mysql 2019-12-17 6.0 MEDIUM N/A
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
CVE-2010-1626 2 Mysql, Oracle 2 Mysql, Mysql 2019-12-17 3.6 LOW N/A
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
CVE-2011-3351 1 Openvas 1 Openvas-scanner 2019-12-11 6.6 MEDIUM 7.1 HIGH
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.
CVE-2019-7183 1 Qnap 1 Qts 2019-12-10 7.5 HIGH 9.8 CRITICAL
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
CVE-2019-3749 1 Dell 1 Command Update 2019-12-10 3.6 LOW 5.5 MEDIUM
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.
CVE-2019-3750 1 Dell 1 Command Update 2019-12-10 3.6 LOW 5.5 MEDIUM
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.
CVE-2019-17445 2 Eracent, Linux 7 Eda Agent, Epa Agent, Epm Agent and 4 more 2019-12-04 2.1 LOW 5.5 MEDIUM
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
CVE-2010-4817 2 Debian, Pithos Project 2 Debian Linux, Pithos 2019-11-25 3.6 LOW 5.5 MEDIUM
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
CVE-2014-1938 1 Rply Project 1 Rply 2019-11-22 2.1 LOW 5.5 MEDIUM
python-rply before 0.7.4 insecurely creates temporary files.
CVE-2014-2312 1 Intel 1 Thermald 2019-11-20 6.6 MEDIUM 5.5 MEDIUM
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
CVE-2008-7273 1 Getfiregpg 1 Iceweasel-firegpg 2019-11-20 4.6 MEDIUM 7.8 HIGH
A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
CVE-2010-3095 1 Mailscanner 1 Mailscanner 2019-11-15 3.3 LOW 4.7 MEDIUM
mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313.
CVE-2013-4655 1 Belkin 2 N900, N900 Firmware 2019-11-14 7.8 HIGH 7.5 HIGH
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
CVE-2011-5271 1 Clusterlabs 1 Pacemaker 2019-11-14 3.3 LOW 5.5 MEDIUM
Pacemaker before 1.1.6 configure script creates temporary files insecurely
CVE-2019-18658 1 Helm 1 Helm 2019-11-14 7.5 HIGH 9.8 CRITICAL
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of Tiller is known to be impacted. This is a client-only issue.
CVE-2010-2064 1 Rpcbind Project 1 Rpcbind 2019-11-05 3.6 LOW 7.1 HIGH
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
CVE-2010-0398 1 Autokey Project 1 Autokey 2019-11-05 5.5 MEDIUM 6.5 MEDIUM
The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.
CVE-2012-2945 1 Apache 1 Hadoop 2019-10-31 5.0 MEDIUM 7.5 HIGH
Hadoop 1.0.3 contains a symlink vulnerability.
CVE-2019-1317 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2019-10-11 5.6 MEDIUM 7.3 HIGH
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.