Vulnerabilities > Debian > Low

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-0770 Symbolic Link vulnerability in DGen Emulator
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
local
low complexity
dgen debian
2.1
2004-12-31 CVE-2004-1179 Local Insecure Temporary File Creation vulnerability in Debian Debmake
The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.
local
low complexity
debian
2.1
2004-12-23 CVE-2004-1336 The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
local
low complexity
debian gentoo
2.1
2004-12-23 CVE-2004-0564 Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files.
local
low complexity
roaring-penguin debian
2.1
2004-05-04 CVE-2003-0618 Information Disclosure vulnerability in Suidperl
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.
local
low complexity
perl debian
2.1
2004-01-10 CVE-2004-1000 Unspecified vulnerability in Debian Lintian 1.20.17.1
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.
local
low complexity
debian
2.1
2003-07-02 CVE-2003-0367 Improper Input Validation vulnerability in multiple products
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
gnu debian CWE-20
2.1
2003-01-17 CVE-2002-1395 Unspecified vulnerability in Debian Internet Message 1330/1410
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.
local
low complexity
debian
2.1
2002-09-05 CVE-2002-0875 Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
local
low complexity
sgi debian
2.1
2002-01-31 CVE-2002-0044 GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
local
low complexity
gnu debian redhat
3.6