CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,522 vulnerabilities with CWE-59
CVE-2021-38570 CRITICAL
Foxit Reader & PhantomPDF <10.1.4 - File Deletion
CVSS 9.1
CVE-2021-38511 HIGH
tar < 0.4.36 - Arbitrary Directory Creation via Symlink Traversal
CVSS 7.5
CVE-2021-21740 LOW
ZTE ZXHN H2640 Firmware - Information Disclosure via Symbolic Link Traversal
CVSS 2.4
CVE-2021-32803 HIGH
node-tar <6.1.2-3.2.3 - File Creation/Overwrite
CVSS 8.2
CVE-2021-36983 HIGH
Replaysorcery - Symlink Following
CVSS 7.8
CVE-2021-32610 HIGH
Archive_Tar < 1.4.14 - Directory Traversal via Symlink Extraction
CVSS 7.1
CVE-2021-32000 LOW
SUSE Linux Enterprise Server clone-master-clean-up - Arbitrary File Deletion via Symlink Following
CVSS 3.2
CVE-2021-1092 HIGH
NVIDIA GPU Display Driver - Path Traversal
CVSS 7.1
CVE-2021-1091 HIGH
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 7.1
CVE-2021-26089 MEDIUM
FortiClient for Mac < 6.4.3 - Privilege Escalation via Symlink Attack
CVSS 6.7
CVE-2021-32518 HIGH
QSAN Storage Manager < 3.3.3 - Arbitrary File Access via Symbolic Link in share_link
CVSS 7.5
CVE-2021-32509 MEDIUM
QSAN Storage Manager < 3.3.3 - Authenticated Absolute Path Traversal via FileviewDoc URL Parameter
CVSS 6.5
CVE-2021-32508 MEDIUM
QSAN Storage Manager < 3.3.3 - Authenticated Absolute Path Traversal via FileStreaming Symbolic Link
CVSS 6.5
CVE-2021-32557 MEDIUM
apport 2.14.1-0ubuntu3-2.14.1-0ubuntu3.29+esm7 - Arbitrary File Write via Symlink
CVSS 5.2
CVE-2021-32555 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32554 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32553 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py read_file()
CVSS 7.3
CVE-2021-32552 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32551 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32550 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-32549 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py read_file()
CVSS 7.3
CVE-2021-32548 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py read_file()
CVSS 7.3
CVE-2021-32547 HIGH
Ubuntu Linux - Information Disclosure via Symbolic Link Following in apport/hookutils.py
CVSS 7.3
CVE-2021-31997 MEDIUM
python-postorius < 1.3.2-lp152.1.2 - Local Privilege Escalation via Symlink Following
CVSS 6.8
CVE-2021-0094 HIGH
Intel Driver & Support Assistant < 20.11.50.9 - Authenticated Privilege Escalation via Improper Link Resolution
CVSS 7.8
Details
Vulnerabilities 1,522
Exploit Likelihood Medium