CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,523 vulnerabilities with CWE-59
CVE-2017-1002101
HIGH
Kubernetes <1.7.14, <1.8.9, <1.9.4 - Info Disclosure
CVSS 8.8
CVE-2017-2619
HIGH
Samba < 4.4.12 - Symlink Race Condition
CVSS 7.5
CVE-2017-5188
MEDIUM
Open Build Service <20170320 - Info Disclosure
CVSS 5.0
CVE-2017-18188
MEDIUM
OpenRC opentmpfiles < 0.1.3 - Arbitrary File Ownership via Hard Link Attack
CVSS 5.5
CVE-2017-18078
HIGH
systemd < 237 - Local Privilege Escalation via Hard Link Ownership Bypass
CVSS 7.8
CVE-2017-15111
MEDIUM
keycloak-httpd-client-install < 0.8 - Insecure Temporary File via Symbolic Link
CVSS 5.5
CVE-2017-1000420
HIGH
Syncthing <0.14.33 - Path Traversal
CVSS 7.5
CVE-2017-16611
MEDIUM
libXfont <1.5.4-2.0.3 - Info Disclosure
CVSS 5.5
CVE-2017-15357
HIGH
Arq < 5.9.7 - Local Privilege Escalation via Symlink Attack on Updater Binary
CVSS 7.4
CVE-2017-7501
HIGH
RPM <4.13.0.2 - Privilege Escalation
CVSS 7.8
CVE-2017-12172
MEDIUM
PostgreSQL 9.2.x-9.6.x < 10.1 - Privilege Escalation via Symbolic Link Attack on Log File
CVSS 6.7
CVE-2017-8806
MEDIUM
PostgreSQL-related scripts for Debian and Ubuntu - Arbitrary File Overwrite via Insecure Symbolic Link Handling
CVSS 5.5
CVE-2017-2916
HIGH
Circle with Disney 2.0.1 - Arbitrary File Write via /api/CONFIG/restore
CVSS 8.8
CVE-2017-1301
MEDIUM
IBM Spectrum Protect <8.1 - Local Privilege Escalation
CVSS 5.5
CVE-2017-12258
MEDIUM
Cisco Unified Communications Manager - XSS
CVSS 6.1
CVE-2017-1000115
HIGH
Mercurial < 4.3 - Arbitrary File Write via Symlink Attack
CVSS 7.5
CVE-2017-7549
MEDIUM
Red Hat OpenStack - Symbolic-Link Attack
CVSS 6.4
CVE-2017-9525
MEDIUM
Cron <3.0pl1-128 - Privilege Escalation
CVSS 6.7
CVE-2017-8108
HIGH
Lynis < 2.5.0 - Arbitrary File Write via Symlink Attack on Temporary File
CVSS 7.8
CVE-2017-6981
HIGH
Apple <10.3.2 - RCE
CVSS 7.8
CVE-2017-7418
MEDIUM
ProFTPD <1.3.5e, <1.3.6rc5 - Privilege Escalation
CVSS 5.5
CVE-2017-2390
MEDIUM
Apple <10.3 - Local Privilege Escalation
CVSS 5.5
CVE-2016-8641
MEDIUM
Nagios 4.2.x - Privilege Escalation
CVSS 6.7
CVE-2016-9595
HIGH
Katello < 3.4.0 - Insecure Temporary File Handling
CVSS 7.3
CVE-2016-9602
HIGH
Qemu < 2.9 - Privilege Escalation via VirtFS Link Following
CVSS 7.6
Details
Vulnerabilities
1,523
Exploit Likelihood
Medium