CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,523 vulnerabilities with CWE-59
CVE-2019-18898
HIGH
SUSE Linux Enterprise Server 15 SP1, openSUSE Factory - Privilege E...
CVSS 7.7
CVE-2019-18932
HIGH
Squid Analysis Report Generator <2.3.11 - Privilege Escalation
CVSS 7.0
CVE-2019-16896
HIGH
K7 Ultimate Security <16.0.0117 - Privilege Escalation
CVSS 7.8
CVE-2019-19695
HIGH
Trend Micro Antivirus for Mac <9.0.1379 - Privilege Escalation
CVSS 7.5
CVE-2019-8463
HIGH
Check Point Endpoint Security Client for Windows < E82.10 - Denial of Service via Service Log File Link Resolution
CVSS 7.5
CVE-2019-6679
LOW
F5 BIG-IP 11.5.9-11.5.10 - Authenticated Arbitrary File Write via Symlink Bypass
CVSS 3.3
CVE-2019-19693
HIGH
Trend Micro Security 2020 - Info Disclosure/DoS
CVSS 7.1
CVE-2019-8789
MEDIUM
iPadOS < 13.2 - User Information Disclosure via Symlink Validation Issue
CVSS 5.5
CVE-2019-8568
MEDIUM
iPhone OS < 12.3 - Unprotected File System Modification via Symlink Validation Issue
CVSS 5.5
CVE-2019-10773
HIGH
Yarn < 1.21.1 - Arbitrary Symlink Creation via Bin Key
CVSS 7.8
CVE-2019-16775
HIGH
npm CLI <6.13.3 - Arbitrary File Write
CVSS 7.7
CVE-2019-18232
HIGH
SafeNet Sentinel LDK License Manager < 7.101 - Privilege Escalation via Symbolic Link
CVSS 7.8
CVE-2019-1483
HIGH
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via AppX Deployment Server Junction Handling
CVSS 7.8
CVE-2019-18575
HIGH
Dell Command Configure <4.2.1 - Code Injection
CVSS 7.1
CVE-2019-7183
CRITICAL
QNAP QTS - Improper Link Resolution Before File Access
CVSS 9.8
CVE-2019-3690
MEDIUM
openSUSE Leap - Privilege Escalation via Symlink Following in chkstat
CVSS 6.8
CVE-2019-3750
MEDIUM
Dell Command Update < 3.1 - Authenticated Arbitrary File Deletion via Symlink Attack
CVSS 5.5
CVE-2019-3749
MEDIUM
Dell Command Update < 3.1 - Authenticated Arbitrary File Deletion via Symlink Attack
CVSS 5.5
CVE-2019-17445
MEDIUM
Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent < 10.2.26 - Arbitrary File Copy via Symbolic Link Following
CVSS 5.5
CVE-2019-19191
HIGH
Shibboleth SP <3.1.0 - Privilege Escalation
CVSS 7.8
CVE-2019-18837
HIGH
crun < 0.10.5 - Improper Link Resolution Before File Access
CVSS 8.6
CVE-2019-1425
MEDIUM
Visual Studio 2017 and 2019 - Elevation of Privilege via Hardlink Validation Bypass
CVSS 6.5
CVE-2019-1423
HIGH
Windows 10 - Elevation of Privilege via StartTileData.dll File Creation
CVSS 7.8
CVE-2019-1422
HIGH
Windows - Elevation of Privilege via iphlpsvc.dll File Creation
CVSS 7.8
CVE-2019-1385
HIGH
KEV
Windows AppX Deployment Extensions - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
1,523
Exploit Likelihood
Medium