CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,523 vulnerabilities with CWE-59
CVE-2016-1255
HIGH
postgresql-common - Privilege Escalation
CVSS 7.8
CVE-2016-3108
HIGH
pulp < 2.8.2-1 - Arbitrary File Write via Symlink Attack
CVSS 7.1
CVE-2016-10374
MEDIUM
perltidy < 2016-03-02 - Arbitrary File Overwrite via Symlink Attack
CVSS 5.5
CVE-2016-9774
HIGH
Debian Linux - Symlink Following
CVSS 7.8
CVE-2016-7619
MEDIUM
iPhone OS < 10.2, macOS < 10.12.2, watchOS < 3.1.3 - Arbitrary File Write via Symlink in libarchive
CVSS 5.5
CVE-2016-4679
MEDIUM
iPhone OS < 10.1, macOS < 10.12.1, tvOS < 10.0.1, watchOS < 3.1 - Arbitrary File Write via libarchive Symlink
CVSS 5.5
CVE-2016-6253
HIGH
NetBSD <7.0 - Local Privilege Escalation
CVSS 7.8
CVE-2016-9566
HIGH
Nagios < 4.2.3 - Privilege Escalation via Symlink Attack on Log File
CVSS 7.8
CVE-2016-6664
HIGH
Oracle MySQL, MariaDB, Percona Server, Percona XtraDB Cluster - Privilege Escalation via Symlink Attack
CVSS 7.0
CVE-2016-1247
HIGH
nginx <1.6.2-5+deb8u3 - Privilege Escalation
CVSS 7.8
CVE-2016-7490
HIGH
Teradata Studio Express 15.12.00.00 - Privilege Escalation via Insecure /tmp File Creation
CVSS 7.8
CVE-2016-3096
HIGH
Fedora < 1.9.6 - Symlink Following
CVSS 7.8
CVE-2015-3147
MEDIUM
Automatic Bug Reporting Tool - Arbitrary File Write via Symlink Attack
CVSS 6.5
CVE-2015-1869
HIGH
Automatic Bug Reporting Tool - Privilege Escalation via Symlink Attack on var_log_messages
CVSS 7.8
CVE-2015-0796
MEDIUM
open buildservice 2.4-2.4.8 - Unrestricted Upload of File with Dangerous Type via Source Service Patch Application
CVSS 6.3
CVE-2015-7529
HIGH
sos 3.0-3.8 - Local Privilege Escalation via Symlink Attack on Temporary Archive File
CVSS 7.8
CVE-2015-5705
HIGH
devscripts <2.15.7 - Command Injection
CVSS 7.5
CVE-2015-5701
MEDIUM
mktexlsr <36855 - Local File Write
CVSS 6.1
CVE-2015-5700
MEDIUM
texlive <36625 - Info Disclosure
CVSS 6.1
CVE-2015-3211
MEDIUM
php-fpm - Arbitrary File Write via Symlink Attack
CVSS 5.5
CVE-2015-3156
MEDIUM
OpenStack Trove < 2014.2.4 - Symlink Attack via Temporary File in Configuration Functions
CVSS 5.5
CVE-2015-3149
MEDIUM
Red Hat Enterprise Linux - Arbitrary File Write via Symlink Attack in Hotspot Component
CVSS 5.5
CVE-2015-3315
HIGH
ABRT raceabrt Privilege Escalation
CVSS 7.8
CVE-2015-6240
HIGH
Ansible < 1.9.2 - Symlink Attack via Chroot, Jail, and Zone Connection Plugins
CVSS 7.8
CVE-2015-8326
MEDIUM
IPTables-Parse <1.6 - Local File Write
CVSS 5.5
Details
Vulnerabilities
1,523
Exploit Likelihood
Medium