CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,520 vulnerabilities with CWE-59
CVE-2022-25856 HIGH
argo-events < 1.7.1 - Path Traversal in GitArtifactReader
CVSS 7.5
CVE-2022-28225 HIGH
Yandex Browser < 22.3.3.684 - Local Privilege Escalation via Symlink Manipulation
CVSS 7.8
CVE-2022-31219 HIGH
Drive Composer - Privilege Escalation
CVSS 7.3
CVE-2022-31218 HIGH
Drive Composer - Privilege Escalation
CVSS 7.8
CVE-2022-31217 HIGH
Drive Composer - Privilege Escalation
CVSS 7.8
CVE-2022-31216 HIGH
Drive Composer - Privilege Escalation
CVSS 7.8
CVE-2022-30687 HIGH
Trend Micro Maximum Security 2022 - SSRF
CVSS 7.1
CVE-2022-26704 HIGH
macOS Monterey <12.4 - Privilege Escalation
CVSS 7.8
CVE-2022-26688 MEDIUM
macOS 10.15-10.15.6 and 11.0-11.6.4 - Arbitrary File Write via Symlink Handling
CVSS 4.4
CVE-2022-30321 HIGH
HashiCorp go-getter < 1.5.11, 2.0.2 - Path Traversal and Command Injection
CVSS 8.6
CVE-2022-31466 HIGH
Quick Heal Total Security <12.1.1.27 - Privilege Escalation
CVSS 7.9
CVE-2022-31258 HIGH
Checkmk <2.1.0b10 - Privilege Escalation
CVSS 8.2
CVE-2022-24904 MEDIUM
Argo CD 0.7.0-2.1.14 - Authenticated Sensitive File Leak via Symlink Following
CVSS 4.3
CVE-2022-30523 HIGH
Trend Micro Password Manager < 5.0.0.1270 - Privilege Escalation via Link Following
CVSS 7.8
CVE-2022-23742 HIGH
Check Point Endpoint Security Client for Windows < E86.40 - Privilege Escalation via Hard Link Attack
CVSS 7.8
CVE-2022-30333 HIGH KEV
UnRAR Path Traversal (CVE-2022-30333)
CVSS 7.5
CVE-2022-20103 MEDIUM
Android - Local Information Disclosure via Symbolic Link Following
CVSS 4.4
CVE-2022-20085 MEDIUM
Android - Local Privilege Escalation via Symbolic Link Following in netdiag
CVSS 6.7
CVE-2022-24372 MEDIUM
Linksys MR9600 <2.0.5 - Info Disclosure
CVSS 4.6
CVE-2022-20720 MEDIUM
Cisco IOS XE IOx Application Hosting - Symlink Path Traversal
CVSS 5.5
CVE-2022-1256 HIGH
McAfee Agent < 5.7.6 - Local Privilege Escalation via Symbolic Link Manipulation
CVSS 7.8
CVE-2022-22962 HIGH
VMware Horizon < 2203 - Local Privilege Escalation via Symbolic Link Manipulation
CVSS 7.8
CVE-2022-20068 MEDIUM
Android - Local Privilege Escalation via Symbolic Link Following in mobile_log_d
CVSS 6.7
CVE-2022-27883 HIGH
Trend Micro Antivirus for Mac < 11.5 - Privilege Escalation via Symlink Attack
CVSS 7.3
CVE-2022-26612 CRITICAL
Apache Hadoop < 3.2.3 - Arbitrary File Write via Symlink Bypass on Windows
CVSS 9.8
Details
Vulnerabilities 1,520
Exploit Likelihood Medium