CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,527 vulnerabilities with CWE-59
CVE-2011-1004
Ruby Arbitrary File Deletion via Symlink Attack
CVE-2011-1031
feh < 1.11.2 - Arbitrary File Creation via Symlink Attack on Temporary File
CVE-2011-0702
feh < 1.11.2 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2011-0754
PHP < 5.3.4 - Improper Link Resolution in SplFileInfo::getType
CVE-2011-0017
Exim <4.72 - Local Privilege Escalation
CVE-2011-0402
dpkg < 1.14.31 - Arbitrary File Modification via Symlink Attack in .pc Directory
CVE-2011-0007
pimd <2.1.5 - Local Privilege Escalation
CVE-2010-4817
MEDIUM
pithos < 0.3.5 - Arbitrary File Overwrite via Symlink
CVSS 5.5
CVE-2010-3095
MEDIUM
mailscanner <4.79.11-2.1 - Local File Overwrite
CVSS 4.7
CVE-2010-0398
MEDIUM
autokey < 0.61.3 - Arbitrary File Write via Symlink Attack
CVSS 6.5
CVE-2010-2064
HIGH
rpcbind 0.2.0 - Privilege Escalation via Symlink Attack on Temporary Files
CVSS 7.1
CVE-2010-5105
Blender <2.63a - Local Privilege Escalation
CVE-2010-4226
HIGH
GNU cpio - Arbitrary File Overwrite via Symlink in RPM Package Archive
CVSS 7.2
CVE-2010-3879
libfuse < 2.8.5 - Unauthenticated Arbitrary Filesystem Unmount via Symlink Attack
CVE-2010-4338
ocrodjvu 0.4.6-1 - Arbitrary File Modification via Symlink Attack on Temporary Files
CVE-2010-4337
gnash 0.8.8 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2010-3847
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
CVE-2010-4173
libsdp < 1.1.104 - Arbitrary File Write via Symlink Attack on /tmp/libsdp.log
CVE-2010-1693
OpenFabrics Enterprise Distribution 1.5.2 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2010-3691
phpCAS < 1.1.3 - Arbitrary File Write via Symlink Attack
CVE-2010-2794
spice-xpi - Arbitrary File Overwrite via Symlink Attack on Log File
CVE-2010-2056
GNU gv < 3.7.0 - Arbitrary File Overwrite via Symlink Attack
CVE-2010-0832
libpam-modules <1.1.0-2ubuntu1.1/1.1.1-2ubuntu5 - Privilege Escalation
CVE-2010-2431
CUPS < 1.4.4 - Arbitrary File Overwrite via Symlink Attack on Cache Files
CVE-2010-2192
pmount 0.9.18 - Arbitrary File Overwrite via Symlink Attack in make_lockdir_name
Details
Vulnerabilities
1,527
Exploit Likelihood
Medium