CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,523 vulnerabilities with CWE-59
CVE-2019-18898 HIGH
SUSE Linux Enterprise Server 15 SP1, openSUSE Factory - Privilege E...
CVSS 7.7
CVE-2019-18932 HIGH
Squid Analysis Report Generator <2.3.11 - Privilege Escalation
CVSS 7.0
CVE-2019-16896 HIGH
K7 Ultimate Security <16.0.0117 - Privilege Escalation
CVSS 7.8
CVE-2019-19695 HIGH
Trend Micro Antivirus for Mac <9.0.1379 - Privilege Escalation
CVSS 7.5
CVE-2019-8463 HIGH
Check Point Endpoint Security Client for Windows < E82.10 - Denial of Service via Service Log File Link Resolution
CVSS 7.5
CVE-2019-6679 LOW
F5 BIG-IP 11.5.9-11.5.10 - Authenticated Arbitrary File Write via Symlink Bypass
CVSS 3.3
CVE-2019-19693 HIGH
Trend Micro Security 2020 - Info Disclosure/DoS
CVSS 7.1
CVE-2019-8789 MEDIUM
iPadOS < 13.2 - User Information Disclosure via Symlink Validation Issue
CVSS 5.5
CVE-2019-8568 MEDIUM
iPhone OS < 12.3 - Unprotected File System Modification via Symlink Validation Issue
CVSS 5.5
CVE-2019-10773 HIGH
Yarn < 1.21.1 - Arbitrary Symlink Creation via Bin Key
CVSS 7.8
CVE-2019-16775 HIGH
npm CLI <6.13.3 - Arbitrary File Write
CVSS 7.7
CVE-2019-18232 HIGH
SafeNet Sentinel LDK License Manager < 7.101 - Privilege Escalation via Symbolic Link
CVSS 7.8
CVE-2019-1483 HIGH
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via AppX Deployment Server Junction Handling
CVSS 7.8
CVE-2019-18575 HIGH
Dell Command Configure <4.2.1 - Code Injection
CVSS 7.1
CVE-2019-7183 CRITICAL
QNAP QTS - Improper Link Resolution Before File Access
CVSS 9.8
CVE-2019-3690 MEDIUM
openSUSE Leap - Privilege Escalation via Symlink Following in chkstat
CVSS 6.8
CVE-2019-3750 MEDIUM
Dell Command Update < 3.1 - Authenticated Arbitrary File Deletion via Symlink Attack
CVSS 5.5
CVE-2019-3749 MEDIUM
Dell Command Update < 3.1 - Authenticated Arbitrary File Deletion via Symlink Attack
CVSS 5.5
CVE-2019-17445 MEDIUM
Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent < 10.2.26 - Arbitrary File Copy via Symbolic Link Following
CVSS 5.5
CVE-2019-19191 HIGH
Shibboleth SP <3.1.0 - Privilege Escalation
CVSS 7.8
CVE-2019-18837 HIGH
crun < 0.10.5 - Improper Link Resolution Before File Access
CVSS 8.6
CVE-2019-1425 MEDIUM
Visual Studio 2017 and 2019 - Elevation of Privilege via Hardlink Validation Bypass
CVSS 6.5
CVE-2019-1423 HIGH
Windows 10 - Elevation of Privilege via StartTileData.dll File Creation
CVSS 7.8
CVE-2019-1422 HIGH
Windows - Elevation of Privilege via iphlpsvc.dll File Creation
CVSS 7.8
CVE-2019-1385 HIGH KEV
Windows AppX Deployment Extensions - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 1,523
Exploit Likelihood Medium