CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,523 vulnerabilities with CWE-59
CVE-2017-1002101 HIGH
Kubernetes <1.7.14, <1.8.9, <1.9.4 - Info Disclosure
CVSS 8.8
CVE-2017-2619 HIGH
Samba < 4.4.12 - Symlink Race Condition
CVSS 7.5
CVE-2017-5188 MEDIUM
Open Build Service <20170320 - Info Disclosure
CVSS 5.0
CVE-2017-18188 MEDIUM
OpenRC opentmpfiles < 0.1.3 - Arbitrary File Ownership via Hard Link Attack
CVSS 5.5
CVE-2017-18078 HIGH
systemd < 237 - Local Privilege Escalation via Hard Link Ownership Bypass
CVSS 7.8
CVE-2017-15111 MEDIUM
keycloak-httpd-client-install < 0.8 - Insecure Temporary File via Symbolic Link
CVSS 5.5
CVE-2017-1000420 HIGH
Syncthing <0.14.33 - Path Traversal
CVSS 7.5
CVE-2017-16611 MEDIUM
libXfont <1.5.4-2.0.3 - Info Disclosure
CVSS 5.5
CVE-2017-15357 HIGH
Arq < 5.9.7 - Local Privilege Escalation via Symlink Attack on Updater Binary
CVSS 7.4
CVE-2017-7501 HIGH
RPM <4.13.0.2 - Privilege Escalation
CVSS 7.8
CVE-2017-12172 MEDIUM
PostgreSQL 9.2.x-9.6.x < 10.1 - Privilege Escalation via Symbolic Link Attack on Log File
CVSS 6.7
CVE-2017-8806 MEDIUM
PostgreSQL-related scripts for Debian and Ubuntu - Arbitrary File Overwrite via Insecure Symbolic Link Handling
CVSS 5.5
CVE-2017-2916 HIGH
Circle with Disney 2.0.1 - Arbitrary File Write via /api/CONFIG/restore
CVSS 8.8
CVE-2017-1301 MEDIUM
IBM Spectrum Protect <8.1 - Local Privilege Escalation
CVSS 5.5
CVE-2017-12258 MEDIUM
Cisco Unified Communications Manager - XSS
CVSS 6.1
CVE-2017-1000115 HIGH
Mercurial < 4.3 - Arbitrary File Write via Symlink Attack
CVSS 7.5
CVE-2017-7549 MEDIUM
Red Hat OpenStack - Symbolic-Link Attack
CVSS 6.4
CVE-2017-9525 MEDIUM
Cron <3.0pl1-128 - Privilege Escalation
CVSS 6.7
CVE-2017-8108 HIGH
Lynis < 2.5.0 - Arbitrary File Write via Symlink Attack on Temporary File
CVSS 7.8
CVE-2017-6981 HIGH
Apple <10.3.2 - RCE
CVSS 7.8
CVE-2017-7418 MEDIUM
ProFTPD <1.3.5e, <1.3.6rc5 - Privilege Escalation
CVSS 5.5
CVE-2017-2390 MEDIUM
Apple <10.3 - Local Privilege Escalation
CVSS 5.5
CVE-2016-8641 MEDIUM
Nagios 4.2.x - Privilege Escalation
CVSS 6.7
CVE-2016-9595 HIGH
Katello < 3.4.0 - Insecure Temporary File Handling
CVSS 7.3
CVE-2016-9602 HIGH
Qemu < 2.9 - Privilege Escalation via VirtFS Link Following
CVSS 7.6
Details
Vulnerabilities 1,523
Exploit Likelihood Medium