CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,523 vulnerabilities with CWE-59
CVE-2018-17567
HIGH
Jekyll <3.6.2, <3.7.4, <3.8.4 - Info Disclosure
CVSS 7.5
CVE-2018-10928
HIGH
Debian Linux < 3.12.14 - Symlink Following
CVSS 8.8
CVE-2018-6557
HIGH
base-files Privilege Escalation via MOTD Update Script (Ubuntu 18.04/18.10)
CVSS 7.0
CVE-2018-15351
MEDIUM
Kraftway 24F2XG Router <3.5.30.1118 - DoS
CVSS 6.5
CVE-2018-10897
HIGH
yum-utils < 1.1.31 - Path Traversal via Remote Repository Configuration
CVSS 8.1
CVE-2018-14335
MEDIUM
H2 <1.4.197 - Info Disclosure
CVSS 6.5
CVE-2018-14329
MEDIUM
HTSlib 1.8 - Local Privilege Escalation
CVSS 4.7
CVE-2018-11637
HIGH
Dialogic PowerMedia XMS <= 3.5 - Unauthenticated Arbitrary File Read via Symlink in Web Root
CVSS 7.5
CVE-2018-13054
HIGH
Debian Linux < 3.8.6 - Symlink Following
CVSS 8.1
CVE-2018-1000544
CRITICAL
rubyzip < 1.2.1 - Directory Traversal and Arbitrary File Write via Zip::File Component
CVSS 9.8
CVE-2018-12026
CRITICAL
Phusion Passenger <5.3.2 - Privilege Escalation
CVSS 9.8
CVE-2018-5107
MEDIUM
Firefox < 58 - Local File Access via Printing Process Symlink Bypass
CVSS 5.3
CVE-2018-12015
HIGH
Perl <5.26.2 - Path Traversal
CVSS 7.5
CVE-2018-10380
HIGH
KDE KWallet <5.12.6 - Privilege Escalation
CVSS 7.8
CVE-2018-10722
HIGH
CylancePROTECT < 1470 - Unauthenticated Privilege Escalation via Symlink Chain in Log Folder
CVSS 7.8
CVE-2018-4112
MEDIUM
macOS < 10.13.4 - Information Disclosure via ATS Symlink Mishandling
CVSS 5.5
CVE-2018-5225
CRITICAL
Atlassian Bitbucket 4.13.0-5.8.1 - Authenticated Remote Code Execution via Symbolic Link
CVSS 9.9
CVE-2018-1196
MEDIUM
Spring Boot <2.0.0.M7 - Privilege Escalation
CVSS 5.9
CVE-2018-1000073
HIGH
RubyGems < 2.2.9, 2.3.6, 2.4.3, 2.5.0 - Directory Traversal in install_location Function
CVSS 7.5
CVE-2018-1063
MEDIUM
Red Hat Enterprise Linux - Improper Link Resolution Before File Access in Context Relabeling
CVSS 4.4
CVE-2018-6954
HIGH
systemd < 237 - Local Privilege Escalation via Symlink Handling in systemd-tmpfiles
CVSS 7.8
CVE-2018-6198
MEDIUM
Tats W3m < 0.5.3 - Symlink Following
CVSS 4.7
CVE-2017-18925
MEDIUM
opentmpfiles <0.3.1 - Privilege Escalation
CVSS 5.5
CVE-2017-7500
HIGH
rpm 4.13.0.0-4.13.0.1 - Improper Link Resolution Before File Access
CVSS 7.3
CVE-2017-15097
MEDIUM
Red Hat Enterprise Linux - Privilege Escalation via PostgreSQL Initialization Scripts
CVSS 6.5
Details
Vulnerabilities
1,523
Exploit Likelihood
Medium