CWE-59— Improper Link Resolution Before File Access (Link Following)
763 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 1 of 16
- CVE-2008-7273HIGHCVSS 7.8EG 7.82019-11-18
A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
- CVE-2009-0035MEDIUMCVSS 5.5EG 5.52019-11-09
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
- CVE-2009-1142MEDIUMCVSS 6.7EG 6.72022-11-23
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
- CVE-2009-1143HIGHCVSS 7.0EG 7.02022-11-23
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
- CVE-2010-0398MEDIUMCVSS 6.5EG 6.52019-10-30
The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.
- CVE-2010-2064HIGHCVSS 7.1EG 7.12019-10-29
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
- CVE-2010-3095MEDIUMCVSS 4.7EG 4.72019-11-12
mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313.
- CVE-2010-4817MEDIUMCVSS 5.5EG 5.52019-11-13
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
- CVE-2011-1136MEDIUMCVSS 4.7EG 4.72019-11-14
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
- CVE-2011-1408HIGHCVSS 8.2EG 8.22019-10-29
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
- CVE-2011-2765HIGHCVSS 7.52018-08-20
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
- CVE-2011-2923MEDIUMCVSS 5.5EG 5.52019-11-19
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by o…
- CVE-2011-2924MEDIUMCVSS 5.5EG 5.52019-11-19
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks b…
- CVE-2011-3351HIGHCVSS 7.1EG 7.12019-11-25
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrit…
- CVE-2011-3618HIGHCVSS 7.8EG 7.82019-11-12
atop: symlink attack possible due to insecure tempfile handling
- CVE-2011-3632HIGHCVSS 7.1EG 7.12019-11-26
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
- CVE-2011-4116LOWCVSS 3.3EG 3.32020-01-31
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
- CVE-2011-5271MEDIUMCVSS 5.5EG 5.52019-11-12
Pacemaker before 1.1.6 configure script creates temporary files insecurely
- CVE-2012-1093HIGHCVSS 7.8EG 7.82020-02-21
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
- CVE-2012-2945HIGHCVSS 7.5EG 7.52019-10-29
Hadoop 1.0.3 contains a symlink vulnerability.
- CVE-2012-6114MEDIUMCVSS 5.5EG 5.52020-01-28
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
- CVE-2013-0159HIGHCVSS 7.12018-05-01
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-…
- CVE-2013-1429MEDIUMCVSS 6.3EG 6.32019-11-07
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
- CVE-2013-1809HIGHCVSS 7.5EG 7.52019-11-07
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
- CVE-2013-1866MEDIUMCVSS 6.1EG 6.12020-01-30
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
- CVE-2013-1867MEDIUMCVSS 6.1EG 6.12020-01-30
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
- CVE-2013-4184MEDIUMCVSS 5.5EG 5.52019-12-10
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
- CVE-2013-4364HIGHCVSS 7.82018-01-08
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
- CVE-2013-4655HIGHCVSS 7.5EG 7.52019-11-13
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
- CVE-2014-0243MEDIUMCVSS 5.5EG 5.52018-07-19
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
- CVE-2014-1420LOWCVSS 3.8EG 3.82020-09-11
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to lau…
- CVE-2014-1859MEDIUMCVSS 5.52018-01-08
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
- CVE-2014-1938MEDIUMCVSS 5.5EG 5.52019-11-21
python-rply before 0.7.4 insecurely creates temporary files.
- CVE-2014-2312MEDIUMCVSS 5.52018-03-26
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
- CVE-2014-3219HIGHCVSS 7.82018-02-09
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
- CVE-2014-4150MEDIUMCVSS 5.52018-07-20
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.
- CVE-2014-4996MEDIUMCVSS 5.5EG 5.52018-01-10
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
- CVE-2014-5509MEDIUMCVSS 5.52018-01-08
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
- CVE-2015-0796MEDIUMCVSS 6.32018-03-02
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement…
- CVE-2015-1869HIGHCVSS 7.8EG 7.82020-01-14
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
- CVE-2015-3147MEDIUMCVSS 6.5EG 6.52020-01-14
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on …
- CVE-2016-8641MEDIUMCVSS 6.72018-08-01
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links befo…
- CVE-2016-9595HIGHCVSS 7.32018-07-27
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary …
- CVE-2016-9602HIGHCVSS 7.62018-04-26
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privile…
- CVE-2017-1000420HIGHCVSS 7.52018-01-02
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
- CVE-2017-1002101HIGHCVSS 8.82018-03-13
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/direc…
- CVE-2017-15097MEDIUMCVSS 6.52018-07-27
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
- CVE-2017-15111MEDIUMCVSS 5.52018-01-20
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
- CVE-2017-18078HIGHCVSS 7.82018-01-29
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vector…
- CVE-2017-18188MEDIUMCVSS 5.52018-02-14
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →