CVE-2023-21722

CVSS v3 Score
5.0
Medium

Vulnerability Description

.NET Framework Denial of Service Vulnerability

CVSS:4.9(Medium)

Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.

CWE-592021
CVSS:4.7(Medium)

Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpi...

CWE-592005
CVSS:4.7(Medium)

mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5...

CWE-592010
CVSS:4.7(Medium)

In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

CWE-592011
CVSS:4.7(Medium)

In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.

CWE-592018
CVSS:4.7(Medium)

keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.prot...

CWE-592018