CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,522 vulnerabilities with CWE-59
CVE-2021-23892
HIGH
McAfee Endpoint Security for Linux Threat Prevention 10.5.0-10.7.5 - Privilege Escalation via TOCTOU Race Condition
CVSS 8.2
CVE-2021-23872
HIGH
McAfee Total Protection < 16.0.32 - Privilege Escalation via File Lock Symbolic Link Manipulation
CVSS 7.8
CVE-2021-31187
HIGH
Windows 10 WalletService - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2021-27851
MEDIUM
GNU Guix 0.11.0-1.2.0 - Local Privilege Escalation via Hardlink Attack on Build Directory
CVSS 5.5
CVE-2021-30356
HIGH
Check Point Identity Agent <R81.018.0000 - DoS
CVSS 8.1
CVE-2021-28098
HIGH
Forescout CounterACT <8.1.4 - Privilege Escalation
CVSS 7.8
CVE-2021-28321
HIGH
Diagnostics Hub Standard Collector Service - Privilege Escalation
CVSS 7.8
CVE-2021-30463
HIGH
VestaCP <0.9.8-24 - Privilege Escalation
CVSS 7.8
CVE-2021-28163
LOW
NetApp Cloud Manager - Exposure of Sensitive Information via Symlink Webapps Directory
CVSS 2.7
CVE-2021-27241
MEDIUM
Avast Premium Security <20.8.2429 - Privilege Escalation
CVSS 6.1
CVE-2021-20197
MEDIUM
GNU binutils < 2.35 - Race Condition in ar, objcopy, strip, ranlib
CVSS 6.3
CVE-2021-28650
MEDIUM
gnome-autoar < 0.3.1 - Directory Traversal via Symlink Handling
CVSS 5.5
CVE-2021-28153
MEDIUM
GNOME GLib <2.66.8 - Info Disclosure
CVSS 5.3
CVE-2021-26889
HIGH
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2021-26887
HIGH
Windows - Elevation of Privilege via Folder Redirection Junction
CVSS 7.8
CVE-2021-26873
HIGH
Windows User Profile Service - Elevation of Privilege via Improper Link Resolution
CVSS 7.0
CVE-2021-26866
HIGH
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via Improper Link Resolution
CVSS 7.1
CVE-2021-26862
HIGH
Windows Installer - Elevation of Privilege via Improper Link Resolution
CVSS 7.0
CVE-2021-3310
HIGH
Western Digital My Cloud OS < 5.10.122 - Symbolic Link Following via SMB and AFP Shares
CVSS 7.8
CVE-2021-21300
HIGH
Git 2.14.2-2.30.0 - Remote Code Execution via Symbolic Link and Clean/Smudge Filter Interaction
CVSS 8.0
CVE-2021-24084
MEDIUM
Windows 10 and Windows Server 2016/2019 - Information Disclosure via Improper Link Resolution
CVSS 5.5
CVE-2021-26720
HIGH
avahi < 0.8-4 - Denial of Service and Arbitrary File Creation via Symlink Attack
CVSS 7.8
CVE-2021-27229
HIGH
Mumble < 1.3.4 - Remote Code Execution via Crafted Server List URL
CVSS 8.8
CVE-2021-23873
HIGH
McAfee Total Protection < 16.0.30 - Privilege Escalation and Arbitrary File Deletion via Junction Link Manipulation
CVSS 7.8
CVE-2021-21131
MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
1,522
Exploit Likelihood
Medium