CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,523 vulnerabilities with CWE-59
CVE-2019-18658
CRITICAL
Helm 2.0.0-2.15.1 - Symlink Following and Denial of Service via Malicious Chart
CVSS 9.8
CVE-2019-18645
MEDIUM
Total Defense Anti-virus <11.5.2.28 - Privilege Escalation
CVSS 5.5
CVE-2019-18466
MEDIUM
libpod < 1.6.0 - Arbitrary File Overwrite via Symlink Resolution in Host Copy Operation
CVSS 5.5
CVE-2019-15627
HIGH
Trend Micro Deep Security Agent 10.0, 11.0, 12.0 - Arbitrary File Deletion via Improper Link Resolution
CVSS 7.1
CVE-2019-1339
HIGH
Windows Error Reporting < - Privilege Escalation
CVSS 7.8
CVE-2019-1317
HIGH
Windows 10 and Windows Server 2016/2019 - Denial of Service via Hard Link Handling
CVSS 7.3
CVE-2019-1315
HIGH
KEV
Windows Error Reporting < - Privilege Escalation
CVSS 7.8
CVE-2019-12672
MEDIUM
Cisco IOS XE - Authenticated Local Code Execution via USB Device File Placement
CVSS 6.8
CVE-2019-1280
HIGH
Windows - Remote Code Execution via .LNK File Processing
CVSS 7.8
CVE-2019-1270
MEDIUM
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via Symbolic Link Attack on WindowsApps Directory
CVSS 5.5
CVE-2019-1267
HIGH
Microsoft Windows - Elevation of Privilege via Symbolic Link Attack in Compatibility Appraiser
CVSS 7.8
CVE-2019-1253
HIGH
KEV
Windows 10 1703-1903 and Windows Server 1803-2019 - Privilege Escalation via AppX Deployment Server Junction Handling
CVSS 7.8
CVE-2019-11396
HIGH
Avira Free Security Suite 10 - Privilege Escalation
CVSS 7.8
CVE-2019-1188
HIGH
Windows 10 and Windows Server 2016/2019 - Remote Code Execution via Malicious LNK File Processing
CVSS 7.5
CVE-2019-5683
HIGH
NVIDIA Windows GPU Display Driver - Improper Link Resolution in User Mode Video Driver Trace Logger
CVSS 7.8
CVE-2019-10152
HIGH
libpod < 1.4.0 - Path Traversal and Arbitrary File Write via Symlink Handling
CVSS 7.2
CVE-2019-13382
HIGH
Snagit 2019.1.2 - Privilege Escalation via Symbolic Link in InvalidPresentations
CVSS 7.8
CVE-2019-11230
MEDIUM
Avast Antivirus < 19.4 - Arbitrary File Rename via Symlink Attack on Update.log
CVSS 4.4
CVE-2019-13915
HIGH
b3log Wide < 1.6.0 - Arbitrary File Read and Write via Editor Code Execution, Symlink in ZIP, or Git Repository Import
CVSS 7.5
CVE-2019-13636
MEDIUM
GNU patch < 2.7.6 - Improper Link Resolution in inp.c and util.c
CVSS 5.9
CVE-2019-1130
HIGH
KEV
Windows AppX Deployment Service - Privilege Escalation
CVSS 7.8
CVE-2019-1129
HIGH
KEV
Windows AppXSVC - Privilege Escalation
CVSS 7.8
CVE-2019-1074
MEDIUM
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via Symbolic Link Attack
CVSS 5.5
CVE-2019-12573
HIGH
Private Internet Access VPN Client v82 - Authenticated Arbitrary File Overwrite via openvpn_launcher Log Option
CVSS 7.1
CVE-2019-12571
HIGH
Private Internet Access VPN Client v0.9.8 beta - Authenticated Arbitrary File Overwrite
CVSS 7.1
Details
Vulnerabilities
1,523
Exploit Likelihood
Medium