CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,525 vulnerabilities with CWE-59
CVE-2011-5146
Bokken < 1.6 and 1.5-x < 1.5-3 - Arbitrary File Overwrite via Symlink Attack on /tmp/graph.dot
CVE-2011-4028
X.Org xserver <1.11.2 - Info Disclosure
CVE-2011-2722
HP Linux Imaging and Printing Project < 3.11.10 - Arbitrary File Write via Symlink Attack on Temporary File
CVE-2011-4105
LightDM <1.0.6 - Local Privilege Escalation
CVE-2011-1384
invscout.rte <2.2.0.19 - Local Privilege Escalation
CVE-2011-4617
virtualenv < 1.5 - Arbitrary File Overwrite via Symlink Attack
CVE-2011-3616
Conky <1.8.1 - Local Privilege Escalation
CVE-2011-3870
Puppet <2.7.5, <2.6.11, <0.25 - Privilege Escalation
CVE-2011-3869
Puppet <2.7.5, <2.6.11, <0.25 - Local File Overwrite
CVE-2011-4060
QNX Neutrino RTOS <6.5.0 - Local Privilege Escalation
CVE-2011-3204
Hammerhead 2.1.4 - Arbitrary File Write via Symlink Attack on Log Files
CVE-2011-0541
fuse < 2.8.5 - Unauthenticated Arbitrary Directory Unmount via Symlink Attack
CVE-2011-2185
Fabric <1.1.0 - Local Privilege Escalation
CVE-2011-2533
Freedesktop Dbus - Symlink Following
CVE-2011-2473
OProfile < 0.9.6 - Arbitrary File Creation via Symlink Attack on opd_pipe
CVE-2011-1920
NetBSD <1.6.2 - Local Privilege Escalation
CVE-2011-0012
SPICE Firefox plug-in <2.4 - Local File Overwrite
CVE-2011-0461
openSUSE aaa_base < 11.2-43.48.1 and < 11.3-8.7.1 - Arbitrary File Overwrite via Symlink Attack on /dev/shm/mtab
CVE-2011-0727
GNOME Display Manager 2.x < 2.32.1 - Symlink Attack via dmrc or Face Icon File
CVE-2011-0441
PHP 5.3.5 - Arbitrary File Deletion via Symlink Attack on /var/lib/php5/
CVE-2011-1073
macOS X - Local File Existence Disclosure and MD5 Checksum Comparison via Symlink Attack on Temporary Files
CVE-2011-1144
PEAR < 1.9.2 - Arbitrary File Overwrite via Symlink Attack on package.xml
CVE-2011-1072
PEAR < 1.9.2 - Arbitrary File Overwrite via Symlink Attack on package.xml
CVE-2011-1004
Ruby Arbitrary File Deletion via Symlink Attack
CVE-2011-1031
feh < 1.11.2 - Arbitrary File Creation via Symlink Attack on Temporary File
Details
Vulnerabilities
1,525
Exploit Likelihood
Medium