CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,525 vulnerabilities with CWE-59
CVE-2015-1196
GNU patch <2.7.1 - Remote Code Execution
CVE-2015-1194
pax 1:20140703 - Arbitrary File Write via Symlink Attack
CVE-2015-1038
p7zip 9.20.1 - Code Injection
CVE-2014-1420 LOW
Ubuntu UI Toolkit < 1.1.1188+14.10.20140813.4-0ubuntu1 - Sensitive Data Exposure via StateSaver Serialization
CVSS 3.8
CVE-2014-1938 MEDIUM
python-rply <0.7.4 - Info Disclosure
CVSS 5.5
CVE-2014-4150 MEDIUM
Scheme 48 - Arbitrary File Write via Symlink Attack on /tmp/s48lose.tmp
CVSS 5.5
CVE-2014-0243 MEDIUM
Check_MK <1.2.5i2p1 - Info Disclosure
CVSS 5.5
CVE-2014-2312 MEDIUM
Thermald - Local Privilege Escalation
CVSS 5.5
CVE-2014-3219 HIGH
fish < 2.1.1 - Arbitrary File Write via Symlink Attack on Temporary Files
CVSS 7.8
CVE-2014-4996 MEDIUM
VladTheEnterprising gem 0.2 - Local File Write
CVSS 5.5
CVE-2014-5509 MEDIUM
Clipboard module for Perl - Arbitrary File Deletion via Symlink Attack on /tmp/clipedit$$
CVSS 5.5
CVE-2014-1859 MEDIUM
NumPy < 1.8.1 - Arbitrary File Write via Symlink Attack on Temporary Files
CVSS 5.5
CVE-2014-4978 MEDIUM
Rawstudio - Local Privilege Escalation
CVSS 5.5
CVE-2014-9512
rsync 3.1.1 - Arbitrary File Write via Symlink Attack
CVE-2014-4480
Apple iOS <8.1.3 & Apple TV <7.0.3 - Path Traversal
CVE-2014-9508
TYPO3 <4.5.39, <6.2.9, <7.0.2 - XSS
CVE-2014-6407
Docker < 1.3.2 - Arbitrary File Write and Remote Code Execution via Symlink Attack in Image Archive
CVE-2014-4703
Nagios Plugins <2.0.2 - Info Disclosure
CVE-2014-3627
Apache Hadoop 0.23.0-0.23.11 and 2.x < 2.5.2 - Symlink Attack via Public Tar Archive Localization
CVE-2014-8585
WordPress Download Manager - Unauthenticated Directory Traversal via fname Parameter
CVE-2014-7206
Advanced Package Tool < 1.0.9.2 - Arbitrary File Write via Symlink Attack on Changelog File
CVE-2014-1875
Capture::Tiny <0.24 - Local File Write
CVE-2014-5459
PHP < 5.6.0 - Arbitrary File Write via PEAR_REST Cache Symlink Attack
CVE-2014-4372
Apple iOS <8, Apple TV <7 - Privilege Escalation
CVE-2014-4199
vm-support 0.88 - Local Info Disclosure
Details
Vulnerabilities 1,525
Exploit Likelihood Medium