CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,523 vulnerabilities with CWE-59
CVE-2015-7724 HIGH
AMD fglrx-driver <15.9 - Privilege Escalation
CVSS 7.8
CVE-2015-7723 HIGH
AMD fglrx-driver <15.7 - Privilege Escalation
CVSS 7.8
CVE-2015-8860 HIGH
Nodejs Node.js < 1.8.4 - Symlink Following
CVSS 7.5
CVE-2015-0858 LOW
Debian Linux - Symlink Following
CVSS 3.3
CVE-2015-6566 HIGH
Zarafa Collaboration Platform < 7.2.1 - Privilege Escalation via Symlink Attack on /tmp/zarafa-vacation-*
CVSS 8.4
CVE-2015-7758 LOW
Gummi 0.6.5 - Path Traversal
CVSS 3.3
CVE-2015-5287
ABRT sosreport Privilege Escalation
CVE-2015-5273
Automatic Bug Reporting Tool < 2.7.1 - Arbitrary File Write via Symlink Attack on unpacked.cpio
CVE-2015-0794
dracut < 037-17.30.1 - Symlink Attack via /tmp/dracut_block_uuid.map
CVE-2015-1338
Apport < 2.19 - Denial of Service and Privilege Escalation via Symlink Attack on vmcore.log
CVE-2015-1335
lxc <1.0.8, <1.1.4 - Privilege Escalation
CVE-2015-6927
vzctl < 4.9.3 - Symlink Attack via VE Private Directory
CVE-2015-5752
Apple iOS <8.4.1 - Privilege Escalation
CVE-2015-3759
Apple iOS <8.4.1 - Privilege Escalation
CVE-2015-1331
LXC < 1.1.2 - Arbitrary File Creation via Symlink Attack on /run/lock/lxc/*
CVE-2015-3436
Zarafa Collaboration Platform <7.1.13, <7.2.1 - Local File Write
CVE-2015-4156
Opensuse < 20150322 - Symlink Following
CVE-2015-4155
GNU Parallel < 20150422 - Arbitrary File Write via Symlink Attack on Temporary File
CVE-2015-3629 HIGH
Libcontainer 1.6.0 - Privilege Escalation
CVSS 7.8
CVE-2015-3627
Libcontainer <1.6.1 - Privilege Escalation
CVE-2015-1130 HIGH KEV
Apple OS X Rootpipe Privilege Escalation
CVSS 7.8
CVE-2015-0556
ARJ Archiver < 3.10.22 - Directory Traversal via Symlink in Archive
CVE-2015-1377
Webmin < 1.720 - Arbitrary File Read via Symlink Attack in Read Mail Module
CVE-2015-1196
GNU patch <2.7.1 - Remote Code Execution
CVE-2015-1194
pax 1:20140703 - Arbitrary File Write via Symlink Attack
Details
Vulnerabilities 1,523
Exploit Likelihood Medium