CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,522 vulnerabilities with CWE-59
CVE-2021-38570
CRITICAL
Foxit Reader & PhantomPDF <10.1.4 - File Deletion
CVSS 9.1
CVE-2021-38511
HIGH
tar < 0.4.36 - Arbitrary Directory Creation via Symlink Traversal
CVSS 7.5
CVE-2021-21740
LOW
ZTE ZXHN H2640 Firmware - Information Disclosure via Symbolic Link Traversal
CVSS 2.4
CVE-2021-32803
HIGH
node-tar <6.1.2-3.2.3 - File Creation/Overwrite
CVSS 8.2
CVE-2021-36983
HIGH
Replaysorcery - Symlink Following
CVSS 7.8
CVE-2021-32610
HIGH
Archive_Tar < 1.4.14 - Directory Traversal via Symlink Extraction
CVSS 7.1
CVE-2021-32000
LOW
SUSE Linux Enterprise Server clone-master-clean-up - Arbitrary File Deletion via Symlink Following
CVSS 3.2
CVE-2021-1092
HIGH
NVIDIA GPU Display Driver - Path Traversal
CVSS 7.1
CVE-2021-1091
HIGH
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 7.1
CVE-2021-26089
MEDIUM
FortiClient for Mac < 6.4.3 - Privilege Escalation via Symlink Attack
CVSS 6.7
CVE-2021-32518
HIGH
QSAN Storage Manager < 3.3.3 - Arbitrary File Access via Symbolic Link in share_link
CVSS 7.5
CVE-2021-32509
MEDIUM
QSAN Storage Manager < 3.3.3 - Authenticated Absolute Path Traversal via FileviewDoc URL Parameter
CVSS 6.5
CVE-2021-32508
MEDIUM
QSAN Storage Manager < 3.3.3 - Authenticated Absolute Path Traversal via FileStreaming Symbolic Link
CVSS 6.5
CVE-2021-32557
MEDIUM
apport 2.14.1-0ubuntu3-2.14.1-0ubuntu3.29+esm7 - Arbitrary File Write via Symlink
CVSS 5.2
CVE-2021-32555
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32554
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32553
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py read_file()
CVSS 7.3
CVE-2021-32552
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32551
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32550
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32549
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py read_file()
CVSS 7.3
CVE-2021-32548
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py read_file()
CVSS 7.3
CVE-2021-32547
HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-31997
MEDIUM
python-postorius < 1.3.2-lp152.1.2 - Local Privilege Escalation via Symlink Following
CVSS 6.8
CVE-2021-0094
HIGH
Intel Driver & Support Assistant < 20.11.50.9 - Authenticated Privilege Escalation via Improper Link Resolution
CVSS 7.8
Details
Vulnerabilities
1,522
Exploit Likelihood
Medium