CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 19 of 35
- CVE-2009-2939MEDIUMCVSS v2 6.9EG 6.92009-09-21
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
- CVE-2009-1893MEDIUMCVSS v2 6.9EG 6.92009-07-17
The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" c…
- CVE-2008-6552MEDIUMCVSS v2 6.9EG 6.92009-03-30
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03…
- CVE-2009-0876MEDIUMCVSS v2 6.9EG 6.92009-03-12
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.
- CVE-2008-6398MEDIUMCVSS v2 6.9EG 6.92009-03-04
sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.
- CVE-2009-0416MEDIUMCVSS v2 6.9EG 6.92009-02-03
The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /var/tmp/key.pem, (2) /va…
- CVE-2008-4990MEDIUMCVSS v2 6.9EG 6.92009-02-02
Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/enomalism2.pid temporary file.
- CVE-2009-0313MEDIUMCVSS v2 6.9EG 6.92009-01-28
winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.
- CVE-2009-0032MEDIUMCVSS v2 6.9EG 6.92009-01-27
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.
- CVE-2008-5746MEDIUMCVSS v2 6.9EG 6.92008-12-29
Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.
- CVE-2008-5743MEDIUMCVSS v2 6.9EG 6.92008-12-26
pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup files with a predictable name, which allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2008-5706MEDIUMCVSS v2 6.9EG 6.92008-12-22
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file.
- CVE-2008-5380MEDIUMCVSS v2 6.9EG 6.92008-12-08
gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, related to the (1) geo…
- CVE-2008-5379MEDIUMCVSS v2 6.9EG 6.92008-12-08
netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts.
- CVE-2008-5378MEDIUMCVSS v2 6.9EG 6.92008-12-08
arb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary file.
- CVE-2008-5377MEDIUMCVSS v2 6.9EG 6.92008-12-08
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
- CVE-2008-5376MEDIUMCVSS v2 6.9EG 6.92008-12-08
editcomment in crip 3.7 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.tag.tmp temporary file.
- CVE-2008-5375MEDIUMCVSS v2 6.9EG 6.92008-12-08
cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file.
- CVE-2008-5374MEDIUMCVSS v2 6.9EG 6.92008-12-08
bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh, (2) aliasconv.bash, and (3) cshtobash scripts.
- CVE-2008-5373MEDIUMCVSS v2 6.9EG 6.92008-12-08
mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.
- CVE-2008-5372MEDIUMCVSS v2 6.9EG 6.92008-12-08
sdm-login in sdm-terminal 0.4.0b allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sdm.autologin.once temporary file.
- CVE-2008-5371MEDIUMCVSS v2 6.9EG 6.92008-12-08
screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file.
- CVE-2008-5370MEDIUMCVSS v2 6.9EG 6.92008-12-08
pvpgn-support-installer in pvpgn 1.8.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pvpgn-support-1.0.tar.gz temporary file.
- CVE-2008-5369MEDIUMCVSS v2 6.9EG 6.92008-12-08
noip2 in noip2 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/noip2 temporary file.
- CVE-2008-5368MEDIUMCVSS v2 6.9EG 6.92008-12-08
muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file.
- CVE-2008-5367MEDIUMCVSS v2 6.9EG 6.92008-12-08
ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.
- CVE-2008-5366MEDIUMCVSS v2 6.9EG 6.92008-12-08
The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/probe-finished or (2) /tmp/ppp-errors temporary file.
- CVE-2008-5313MEDIUMCVSS v2 6.9EG 6.92008-12-03
mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and…
- CVE-2008-5312MEDIUMCVSS v2 6.9EG 6.92008-12-03
mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new…
- CVE-2008-5299MEDIUMCVSS v2 6.9EG 6.92008-12-01
chm2pdf 0.9 allows user-assisted local users to delete arbitrary files via a symlink attack on .chm files in the (1) /tmp/chm2pdf/work or (2) /tmp/chm2pdf/orig temporary directories.
- CVE-2008-5157MEDIUMCVSS v2 6.9EG 6.92008-11-18
tau 2.16.4 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/makefile.tau.*.##### or (2) /tmp/makefile.tau*.##### temporary file, related to the (a) tau_cxx, (b) tau_f90, and (c) tau_cc scripts.
- CVE-2008-5156MEDIUMCVSS v2 6.9EG 6.92008-11-18
si_mkbootserver in systemimager-server 3.6.3 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.inetd.conf or (2) /tmp/pxe.conf.*.tmp temporary file.
- CVE-2008-5154MEDIUMCVSS v2 6.9EG 6.92008-11-18
bluetooth.rc in p3nfs 5.19 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/blue.log temporary file.
- CVE-2008-5152MEDIUMCVSS v2 6.9EG 6.92008-11-18
inmail-show in mh-book 200605 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/inmail#####.log or (2) /tmp/inmail#####.stdin temporary file.
- CVE-2008-5151MEDIUMCVSS v2 6.9EG 6.92008-11-18
test_parser.py in mayavi 1.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/err.log temporary file.
- CVE-2008-5150MEDIUMCVSS v2 6.9EG 6.92008-11-18
sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.
- CVE-2008-5149MEDIUMCVSS v2 6.9EG 6.92008-11-18
fwd_check.sh in libncbi6 6.1.20080302 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.
- CVE-2008-5148MEDIUMCVSS v2 6.9EG 6.92008-11-18
sch2eaglepos.sh in geda-gnetlist 1.4.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.
- CVE-2008-5147MEDIUMCVSS v2 6.9EG 6.92008-11-18
test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/outer.odt temporary file.
- CVE-2008-5146MEDIUMCVSS v2 6.9EG 6.92008-11-18
add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file.
- CVE-2008-5145MEDIUMCVSS v2 6.9EG 6.92008-11-18
ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.
- CVE-2008-5144MEDIUMCVSS v2 6.9EG 6.92008-11-18
nvidia-cg-toolkit-installer in nvidia-cg-toolkit 2.0.0015 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvidia-cg-toolkit-manifest temporary file.
- CVE-2008-5143MEDIUMCVSS v2 6.9EG 6.92008-11-18
mgt-helper in multi-gnome-terminal 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.debug or (2) /tmp/*.env temporary file.
- CVE-2008-5142MEDIUMCVSS v2 6.9EG 6.92008-11-18
sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### temporary file.
- CVE-2008-5141MEDIUMCVSS v2 6.9EG 6.92008-11-18
flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file.
- CVE-2008-5140MEDIUMCVSS v2 6.9EG 6.92008-11-18
trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file.
- CVE-2008-5139MEDIUMCVSS v2 6.9EG 6.92008-11-18
updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.
- CVE-2008-5138MEDIUMCVSS v2 6.9EG 6.92008-11-18
passwdehd in libpam-mount 0.43 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/passwdehd.##### temporary file.
- CVE-2008-5137MEDIUMCVSS v2 6.9EG 6.92008-11-18
tkman in tkman 2.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/tkman##### or (2) /tmp/ll temporary file.
- CVE-2008-5136MEDIUMCVSS v2 6.9EG 6.92008-11-18
tkusr in tkusr 0.82 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/tkusr.pgm temporary file.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →