CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2008-4983

    Last Modified: 23 Apr 2026

    scilab-bin 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/SciLink#####1, (b) /tmp/SciLink#####2, (c) /tmp/SciLink#####3, (d) /tmp/*.#####, (e) /tmp/*.#####.res, (f) /tmp/*.#####.err, and (g) /tmp/*.#####.diff temporary files, related to the (1) scilink, (2) scidoc, and (3) scidem scripts.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4977

    Last Modified: 23 Apr 2026

    postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4970

    Last Modified: 23 Apr 2026

    runiozone in lustre 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/iozone.log temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4969

    Last Modified: 23 Apr 2026

    ltp-network-test 20060918 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/vsftpd.conf, (b) /tmp/udp/2/*, (c) /tmp/tcp/2/*, (d) /tmp/udp/3/*, (e) /tmp/tcp/3/*, (f) /tmp/nfs_fsstress.udp.2.log, (g) /tmp/nfs_fsstress.udp.3.log, (h) /tmp/nfs_fsstress.tcp.2.log, (i) /tmp/nfs_fsstress.tcp.3.log, and (j) /tmp/nfs_fsstress.sardata temporary files, related to the (1) ftp_setup_vsftp_conf and (2) nfs_fsstress.sh scripts.

    Published: 6 Nov 2008
    8.3
    High

    CVE-2008-4395

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4964

    Last Modified: 23 Apr 2026

    filters/any-UTF8 in konwert 1.8 allows local users to delete arbitrary files via a symlink attack on a /tmp/any-##### temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4965

    Last Modified: 23 Apr 2026

    liguidsoap.py in liguidsoap 0.3.8.1+2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/liguidsoap.liq, (2) /tmp/lig.#####.log, and (3) /tmp/emission.ogg temporary files.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4971

    Last Modified: 23 Apr 2026

    mafft-homologs in mafft 6.240 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/_vf#?????, (2) /tmp/_if#?????, (3) /tmp/_pf#?????, (4) /tmp/_af#?????, (5) /tmp/_rid#?????, (6) /tmp/_res#?????, (7) /tmp/_q#?????, and (8) /tmp/_bf#????? temporary files.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4972

    Last Modified: 23 Apr 2026

    mailgo in mgt 2.31 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mailgo##### temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4973

    Last Modified: 23 Apr 2026

    i2myspell in myspell 3.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/i2my#####.1 and (2) /tmp/i2my#####.2 temporary files.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4974

    Last Modified: 23 Apr 2026

    rrdedit in netmrg 0.20 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*.xml and (2) /tmp/*.backup temporary files.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4978

    Last Modified: 23 Apr 2026

    radiance 3R9+20080530 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/opt.fmt, (b) /tmp/out#####.fmt, (c) /tmp/tf#####.dat, (d) /tmp/gsf#####, (e) /tmp/sc#####.sh, (f) /tmp/il#####.pic, (g) /tmp/tl#####.pic, (h) /tmp/ds#####.pic, (i) /tmp/tfa#####, and (j) /tmp/sed##### temporary files, related to the (1) optics2rad, (2) pdelta, (3) dayfact, and (4) raddepend scripts.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4979

    Last Modified: 23 Apr 2026

    getipacctg in rancid 2.3.2~a8 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/ipacct.#####.prefixes, (2) /tmp/ipacct.#####.sorted, (3) /tmp/ipacct.#####.pl, and (4) /tmp/ipacct.##### temporary files.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4980

    Last Modified: 23 Apr 2026

    delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4981

    Last Modified: 23 Apr 2026

    perl.robot in realtimebattle 1.0.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl.robot.log temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4986

    Last Modified: 23 Apr 2026

    wims 3.62 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/env#####, (b) /tmp/sed#####, and (c) /tmp/referer-home.log temporary files, related to the (1) coqweb and (2) account.sh scripts.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4988

    Last Modified: 23 Apr 2026

    pscal in xcal 4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pscal##### temporary file.

    Published: 6 Nov 2008
    7.1
    High

    CVE-2008-4963

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the VLAN Trunking Protocol (VTP) implementation on Cisco IOS and CatOS, when the VTP operating mode is not transparent, allows remote attackers to cause a denial of service (device reload or hang) via a crafted VTP packet sent to a switch interface configured as a trunk port.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4976

    Last Modified: 23 Apr 2026

    ogle 0.9.2 and ogle-mmx 0.9.2 allow local users to overwrite arbitrary files via a symlink attack on (a) /tmp/ogle_audio.#####, (b) /tmp/ogle_cli.#####, (c) /tmp/ogle_ctrl.#####, (d) /tmp/ogle_gui.#####, (e) /tmp/ogle_mpeg_ps.#####, (f) /tmp/ogle_mpeg_vs.#####, (g) /tmp/ogle_nav.#####, and (h) /tmp/ogle_vout.#####, temporary files, related to the (1) ogle_audio_debug, (2) ogle_cli_debug, (3) ogle_ctrl_debug, (4) ogle_gui_debug, (5) ogle_mpeg_ps_debug, (6) ogle_mpeg_vs_debug, (7) ogle_nav_debug, and (8) ogle_vout_debug scripts.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4966

    Last Modified: 23 Apr 2026

    linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly##### temporary files, related to the (1) maysnap and (2) maytest scripts.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4967

    Last Modified: 23 Apr 2026

    linuxtrade 3.65 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/bwk, (b) /tmp/zzz, and (c) /tmp/ggg temporary files, related to the (1) linuxtrade.bwkvol, (2) linuxtrade.wn, and (3) moneyam.helper scripts.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4968

    Last Modified: 23 Apr 2026

    The (1) rccs and (2) STUFF scripts in lmbench 3.0-a7 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/sdiff.##### temporary file.

    Published: 6 Nov 2008
    6.5
    Medium

    CVE-2008-5027

    Last Modified: 23 Apr 2026

    The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and trigger execution of arbitrary programs by this process, via an (a) custom form or a (b) browser addon.

    Published: 6 Nov 2008
    4
    Medium

    CVE-2008-5113

    Last Modified: 23 Apr 2026

    WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

    Published: 6 Nov 2008
    4.9
    Medium

    CVE-2008-5029

    Last Modified: 23 Apr 2026

    The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.

    Published: 6 Nov 2008
    6.8
    Medium

    CVE-2008-5028

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4936

    Last Modified: 23 Apr 2026

    faxspool in mgetty 1.1.36 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/faxsp.##### temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4938

    Last Modified: 23 Apr 2026

    aegis 4.24 and aegis-web 4.24 allow local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####, (b) /tmp/#####.intro, (c) /tmp/aegis.#####.ae, (d) /tmp/aegis.#####, (e) /tmp/aegis.#####.1, (f) /tmp/aegis.#####.2, (g) /tmp/aegis.#####.log, and (h) /tmp/aegis.#####.out temporary files, related to the (1) bng_dvlpd.sh, (2) bng_rvwd.sh, (3) awt_dvlp.sh, (4) awt_intgrtn.sh, and (5) aegis.cgi scripts.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4944

    Last Modified: 23 Apr 2026

    writtercontrol in cdcontrol 1.90 allows local users to overwrite arbitrary files via a symlink attack on /tmp/v-recorder*-out temporary files.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4945

    Last Modified: 23 Apr 2026

    amlabel-cdrw in cdrw-taper 0.4 might allow local users to overwrite arbitrary files via a symlink attack involving a /tmp/amlabel-cdrw.##### temporary directory.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4949

    Last Modified: 23 Apr 2026

    dist 3.5 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/cil#####, (b) /tmp/pdo#####, and (c) /tmp/pdn##### temporary files, related to the (1) patcil and (2) patdiff scripts.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4950

    Last Modified: 23 Apr 2026

    gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that "There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4951

    Last Modified: 23 Apr 2026

    dtc 0.29.6 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/awstats.log, (b) /tmp/spam.log.#####, and (c) /tmp/spam_err.log temporary files, related to the (1) accesslog.php and (2) sa-wrapper scripts.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4952

    Last Modified: 23 Apr 2026

    emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4953

    Last Modified: 23 Apr 2026

    firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4954

    Last Modified: 23 Apr 2026

    mead.pl in fml 4.0.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/debugbuf temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4948

    Last Modified: 23 Apr 2026

    fest.pl in digitaldj 0.7.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ddj_fest.tmp temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4958

    Last Modified: 23 Apr 2026

    gdrae in gdrae 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gdrae/palabra temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4960

    Last Modified: 23 Apr 2026

    impose in impose+ 0.2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-tmp.ps and (2) /tmp/bboxx-* temporary files.

    Published: 5 Nov 2008
    4.3
    Medium

    CVE-2008-4816

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.

    Published: 5 Nov 2008
    4.3
    Medium

    CVE-2008-4931

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.

    Published: 5 Nov 2008
    9
    Critical

    CVE-2008-4932

    Last Modified: 23 Apr 2026

    webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4947

    Last Modified: 23 Apr 2026

    dhis-dummy-log-engine in dhis-server 5.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/dhis-dummy-log-engine.log temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4959

    Last Modified: 23 Apr 2026

    geo-code in gpsdrive-scripts 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/geo.google, (2) /tmp/geo.yahoo, (3) /tmp/geo.coords, and (4) /tmp/geo#####.coords temporary files.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4942

    Last Modified: 23 Apr 2026

    audiolink in audiolink 0.05 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/audiolink.db.tmp and (2) /tmp/audiolink.tb.tmp temporary files.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4943

    Last Modified: 23 Apr 2026

    bulmages-servers 0.11.1 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/error.txt, (b) /tmp/errores.txt, and possibly other temporary files, related to the (1) creabulmafact, (2) creabulmacont, and possibly (3) actualizabulmacont, (4) installbulmages-db, and (5) actualizabulmafact scripts.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4957

    Last Modified: 23 Apr 2026

    find_flags in Kitware GCC-XML (gccxml) 0.9.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.cxx temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4935

    Last Modified: 23 Apr 2026

    asciiview in aview 1.3.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/aview#####.pgm temporary file.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4939

    Last Modified: 23 Apr 2026

    apertium 3.0.7 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####.lex.cc, (b) /tmp/#####.deformat.l, (c) /tmp/#####.reformat.l, (d) /tmp/#####docxorig, (e) /tmp/#####docxsalida.zip, (f) /tmp/#####xlsxembed, (g) /tmp/#####xlsxorig, and (h) /tmp/#####xslxsalida.zip temporary files, related to the (1) apertium-gen-deformat, (2) apertium-gen-reformat, and (3) apertium scripts.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4940

    Last Modified: 23 Apr 2026

    xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file.

    Published: 5 Nov 2008