CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,750 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 28 of 35
- CVE-2020-6015MEDIUMCVSS 5.5EG 5.52020-11-05
Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations.
- CVE-2018-21269MEDIUMCVSS 5.5EG 5.52020-10-27
checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink.
- CVE-2017-18925MEDIUMCVSS 5.5EG 5.52020-10-26
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.
- CVE-2020-25289MEDIUMCVSS 5.5EG 5.52020-09-13
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
- CVE-2020-7325MEDIUMCVSS 5.5EG 5.52020-09-09
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to a…
- CVE-2020-24332MEDIUMCVSS 5.5EG 5.52020-08-13
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which c…
- CVE-2020-0779MEDIUMCVSS 5.5EG 5.52020-03-12
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-20…
- CVE-2012-6114MEDIUMCVSS 5.5EG 5.52020-01-28
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
- CVE-2020-0616MEDIUMCVSS 5.5EG 5.52020-01-14
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
- CVE-2019-8789MEDIUMCVSS 5.5EG 5.52019-12-18
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may l…
- CVE-2019-8568MEDIUMCVSS 5.5EG 5.52019-12-18
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify prot…
- CVE-2013-4184MEDIUMCVSS 5.5EG 5.52019-12-10
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
- CVE-2019-3750MEDIUMCVSS 5.5EG 5.52019-12-03
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symli…
- CVE-2019-3749MEDIUMCVSS 5.5EG 5.52019-12-03
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symli…
- CVE-2019-17445MEDIUMCVSS 5.5EG 5.52019-11-22
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symb…
- CVE-2014-1938MEDIUMCVSS 5.5EG 5.52019-11-21
python-rply before 0.7.4 insecurely creates temporary files.
- CVE-2011-2924MEDIUMCVSS 5.5EG 5.52019-11-19
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks b…
- CVE-2011-2923MEDIUMCVSS 5.5EG 5.52019-11-19
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by o…
- CVE-2010-4817MEDIUMCVSS 5.5EG 5.52019-11-13
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
- CVE-2011-5271MEDIUMCVSS 5.5EG 5.52019-11-12
Pacemaker before 1.1.6 configure script creates temporary files insecurely
- CVE-2009-0035MEDIUMCVSS 5.5EG 5.52019-11-09
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
- CVE-2019-18645MEDIUMCVSS 5.5EG 5.52019-10-31
The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.
- CVE-2019-18466MEDIUMCVSS 5.5EG 5.52019-10-28
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container im…
- CVE-2019-1270MEDIUMCVSS 5.5EG 5.52019-09-11
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
- CVE-2019-1074MEDIUMCVSS 5.5EG 5.52019-07-15
An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could potentially ac…
- CVE-2019-13229MEDIUMCVSS 5.5EG 5.52019-07-04
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or ove…
- CVE-2019-13227MEDIUMCVSS 5.5EG 5.52019-07-04
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file …
- CVE-2019-11879MEDIUMCVSS 5.5EG 5.52019-05-10
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks i…
- CVE-2014-4150MEDIUMCVSS 5.5EG 5.52018-07-20
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.
- CVE-2014-0243MEDIUMCVSS 5.5EG 5.52018-07-19
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
- CVE-2018-4112MEDIUMCVSS 5.5EG 5.52018-04-03
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.
- CVE-2014-2312MEDIUMCVSS 5.5EG 5.52018-03-26
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
- CVE-2017-18188MEDIUMCVSS 5.5EG 5.52018-02-14
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.
- CVE-2017-15111MEDIUMCVSS 5.5EG 5.52018-01-20
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
- CVE-2014-4996MEDIUMCVSS 5.5EG 5.52018-01-10
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
- CVE-2014-5509MEDIUMCVSS 5.5EG 5.52018-01-08
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
- CVE-2014-1859MEDIUMCVSS 5.5EG 5.52018-01-08
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
- CVE-2014-4978MEDIUMCVSS 5.5EG 5.52017-12-29
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
- CVE-2017-16611MEDIUMCVSS 5.5EG 5.52017-12-01
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
- CVE-2017-8806MEDIUMCVSS 5.5EG 5.52017-11-13
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links in…
- CVE-2011-2684MEDIUMCVSS 5.5EG 5.52017-10-23
foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write ove…
- CVE-2017-1301MEDIUMCVSS 5.5EG 5.52017-10-05
IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbol…
- CVE-2015-3211MEDIUMCVSS 5.5EG 5.52017-08-25
php-fpm allows local users to write to or create arbitrary files via a symlink attack.
- CVE-2015-3156MEDIUMCVSS 5.5EG 5.52017-08-11
The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/config.py, write_config function in trove/guestagent/datas…
- CVE-2015-3149MEDIUMCVSS 5.5EG 5.52017-07-25
The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.
- CVE-2015-8326MEDIUMCVSS 5.5EG 5.52017-06-07
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
- CVE-2016-10374MEDIUMCVSS 5.5EG 5.52017-05-17
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users …
- CVE-2017-7418MEDIUMCVSS 5.5EG 5.52017-04-04
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowC…
- CVE-2017-2390MEDIUMCVSS 5.5EG 5.52017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in the "libarchive" comp…
- CVE-2016-7619MEDIUMCVSS 5.5EG 5.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "libarchive" component, which allows local users to write to arbitra…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →