CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,520 vulnerabilities with CWE-59
CVE-2023-20008
MEDIUM
Cisco TelePresence CE - Local Privilege Escalation
CVSS 4.4
CVE-2023-21760
HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.1
CVE-2023-21725
MEDIUM
Windows Malicious Software Removal Tool - Privilege Escalation
CVSS 6.3
CVE-2023-21678
HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.8
CVE-2023-21542
HIGH
Windows Installer - Privilege Escalation
CVSS 7.0
CVE-2022-46869
HIGH
Acronis Cyber Protect Home Office <build 40278 - Privilege Escalation
CVSS 7.8
CVE-2022-48579
HIGH
UnRAR < 6.2.3 - Directory Traversal via Symlink Chains
CVSS 7.5
CVE-2022-38730
MEDIUM
Docker Desktop for Windows <4.6 - Code Injection
CVSS 6.3
CVE-2022-34292
HIGH
Docker Desktop < 4.6.0 - Arbitrary File Write via Symlink Attack on hyperv/create API
CVSS 7.1
CVE-2022-31647
HIGH
Docker Desktop < 4.6.0 - Arbitrary File Deletion via hyperv/destroy API DataFolder Symlink
CVSS 7.1
CVE-2022-43293
MEDIUM
Wacom Driver <6.3.46-1 - Arbitrary File Write
CVSS 5.9
CVE-2022-38604
HIGH
Wacom Driver <6.3.46-1 - Privilege Escalation
CVSS 7.3
CVE-2022-47188
HIGH
Generex UPS CS141 <2.06 - Info Disclosure
CVSS 7.5
CVE-2022-22582
MEDIUM
macOS < 11.6.5 - Arbitrary File Write via Symlink Validation Issue
CVSS 5.5
CVE-2022-45697
HIGH
Razer Central < 7.8.0.381 - Arbitrary File Deletion via Accounts Directory Handling
CVSS 7.8
CVE-2022-42292
MEDIUM
NVIDIA GeForce Experience < 3.27.0.112 - Privilege Escalation via Symbolic Link Attack in NVContainer
CVSS 5.0
CVE-2022-42291
HIGH
NVIDIA GeForce Experience < 3.27.0.112 - Data Tampering via Installer Windows Junction Handling
CVSS 8.2
CVE-2022-45440
MEDIUM
Zyxel AX7501-B0 Firmware < 5.17(ABPC.3)C0 - Authenticated Directory Traversal via FTP Symbolic Link Processing
CVSS 4.4
CVE-2022-3592
MEDIUM
Samba 4.17.0-4.17.1 - Symbolic Link Following via SMB1 Unix Extensions or NFS
CVSS 6.5
CVE-2022-38482
MEDIUM
Mega HOPEX 15.2.0.6110 - Improper Link Resolution Before File Access
CVSS 4.3
CVE-2022-36943
HIGH
SSZipArchive < 2.5.3 - Arbitrary File Write via Symlink Path Traversal
CVSS 8.1
CVE-2022-45798
HIGH
Trend Micro Apex One - Privilege Escalation via Damage Cleanup Engine Symbolic Link Abuse
CVSS 7.8
CVE-2022-45412
HIGH
Firefox < 107.0 and Firefox ESR < 102.5 - Information Disclosure via Symlink Resolution
CVSS 8.8
CVE-2022-4563
HIGH
Freedom of the Press SecureDrop - Symlink Following
CVSS 7.8
CVE-2022-4122
MEDIUM
Podman < 4.5.0 - Information Disclosure via Symlink Following in .containerignore and .dockerignore
CVSS 5.3
Details
Vulnerabilities
1,520
Exploit Likelihood
Medium