Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-11-07 CVE-2008-4993 Link Following vulnerability in XEN 3.2.1
qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.
local
xen CWE-59
6.9
2008-11-07 CVE-2008-4992 Permissions, Privileges, and Access Controls vulnerability in SUN products
The SPARC hypervisor in Sun System Firmware 6.6.3 through 6.6.5 and 7.1.3 through 7.1.3.e on UltraSPARC T1, T2, and T2+ processors allows logical domain users to access memory in other logical domains via unknown vectors.
local
low complexity
sun CWE-264
4.6
2008-11-06 CVE-2008-4988 Link Following vulnerability in Lars Bahner Xcal 4.1
pscal in xcal 4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pscal##### temporary file.
6.9
2008-11-06 CVE-2008-4987 Link Following vulnerability in Xastir 1.9.2
xastir 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/ldconfig.tmp, (b) /tmp/ldconf.tmp, and (c) /tmp/ld.so.conf temporary files, related to the (1) get-maptools.sh and (2) get_shapelib.sh scripts.
local
xastir CWE-59
6.9
2008-11-06 CVE-2008-4986 Link Following vulnerability in Georges Khaznadar Wims 3.6.2
wims 3.62 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/env#####, (b) /tmp/sed#####, and (c) /tmp/referer-home.log temporary files, related to the (1) coqweb and (2) account.sh scripts.
6.9
2008-11-06 CVE-2008-4985 Link Following vulnerability in Cadsoft VDR 1.6.0
vdrleaktest in Video Disk Recorder (aka vdr-dbg or vdr) 1.6.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/memleaktest.log temporary file.
local
cadsoft CWE-59
6.9
2008-11-06 CVE-2008-4984 Link Following vulnerability in Freedesktop Scratchbox2 1.99.0.24
scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstamp.##### temporary files, related to the (1) dpkg-checkbuilddeps and (2) sb2-check-pkg-mappings scripts.
6.9
2008-11-06 CVE-2008-4983 Link Following vulnerability in Scilab Scilab-Bin 4.1.2
scilab-bin 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/SciLink#####1, (b) /tmp/SciLink#####2, (c) /tmp/SciLink#####3, (d) /tmp/*.#####, (e) /tmp/*.#####.res, (f) /tmp/*.#####.err, and (g) /tmp/*.#####.diff temporary files, related to the (1) scilink, (2) scidoc, and (3) scidem scripts.
local
scilab CWE-59
6.9
2008-11-06 CVE-2008-4982 Link Following vulnerability in John Horne Rkhunter 1.3.2
rkhunter in rkhunter 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rkhunter-debug temporary file.
6.9
2008-11-06 CVE-2008-4981 Link Following vulnerability in Remi Vanicat Realtimebattle 1.0.8
perl.robot in realtimebattle 1.0.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl.robot.log temporary file.
6.9