CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,522 vulnerabilities with CWE-59
CVE-2021-1491
MEDIUM
Cisco Catalyst SD-WAN Manager - Authenticated Arbitrary File Read via File Reference Manipulation
CVSS 6.5
CVE-2021-4287
MEDIUM
ReFirm Labs binwalk <2.3.2 - Symlink Following
CVSS 5.0
CVE-2021-35939
MEDIUM
Fix incomplete - Privilege Escalation
CVSS 6.7
CVE-2021-35938
MEDIUM
rpm < 4.18.0 - Privilege Escalation via Symbolic Link Attack
CVSS 6.7
CVE-2021-35937
MEDIUM
rpm < 4.18.0 - Unauthenticated Time-of-check Time-of-use Race Condition
CVSS 6.4
CVE-2021-31566
HIGH
libarchive < 3.5.2 - Improper Link Resolution Before File Access
CVSS 7.8
CVE-2021-23177
HIGH
Archive Extractor - Privilege Escalation
CVSS 7.8
CVE-2021-42056
MEDIUM
Thales Safenet Authentication Client < 10.7.7 - Arbitrary File Write via Symlink Attack
CVSS 6.7
CVE-2021-25261
HIGH
Yandex Browser <22.5.0.862 - Privilege Escalation
CVSS 7.8
CVE-2021-41641
HIGH
Deno <=1.14.0 - Symbolic Link Resolution Bypass via Deno.symlink
CVSS 8.4
CVE-2021-44052
MEDIUM
QNAP QTS 4.3.3-5.0.0, QuTS hero <4.5.4.1971, QuTScloud <5.0.1.1998 Path Traversal
CVSS 6.5
CVE-2021-27117
HIGH
beego < 2.0.2 - Symlink Attack via GetCPUProfile Function
CVSS 7.8
CVE-2021-27116
HIGH
beego <= 2.0.2 - Symlink Attack via MemProf Function
CVSS 7.8
CVE-2021-44141
MEDIUM
Samba < 4.15.5 - Unauthenticated Exposure of Sensitive Information via SMB1 Symlink
CVSS 4.3
CVE-2021-44730
HIGH
snapd < 2.54.3 - Privilege Escalation via Hardlink Attack on snap-confine Binary
CVSS 7.8
CVE-2021-23521
MEDIUM
juce < 6.1.5 - Arbitrary File Write via Symbolic Link in Archive Extraction
CVSS 5.5
CVE-2021-41551
MEDIUM
Leostream Connection Broker 9.0.40.17 - Directory Traversal via ZIP File Symbolic Link
CVSS 4.9
CVE-2021-45442
HIGH
Trendmicro Apex One - Symlink Following
CVSS 7.1
CVE-2021-45231
HIGH
Trend Micro Apex One and Worry-Free Business Security - Privilege Escalation via Link Following
CVSS 7.8
CVE-2021-44024
HIGH
Trend Micro Apex One and Worry-Free Business Security - Denial of Service via Link Following
CVSS 7.1
CVE-2021-20153
MEDIUM
Trendnet AC2600 TEW-827DRU 2.08B01 - Remote Code Execution via BitTorrent Symlink Attack
CVSS 6.8
CVE-2021-23772
HIGH
iris-go/iris and kataras/iris - Arbitrary File Write via UploadFormFiles Method
CVSS 7.5
CVE-2021-44023
HIGH
Trend Micro Security 2021 < 17.0 - Denial of Service via PC Health Checkup Symlink Abuse
CVSS 7.1
CVE-2021-43238
HIGH
Windows Remote Access - Privilege Escalation
CVSS 7.8
CVE-2021-43237
HIGH
Windows Setup < - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
1,522
Exploit Likelihood
Medium