CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,527 vulnerabilities with CWE-59
CVE-2010-0546
Apple Mac OS X 10.5.8 and 10.6 < 10.6.4 - Arbitrary Folder Deletion via Symlink Attack
CVE-2010-2053
emesene < 1.6.2 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2010-2027
Mathematica 7 - Arbitrary File Overwrite via Symlink Attack on /tmp/MathLink/ or /tmp/fonts$$.conf
CVE-2010-1626
MySQL < 5.1.46 - Unauthenticated Arbitrary File Deletion via MyISAM Table Symlink Attack
CVE-2010-1160
GNU nano <2.2.4 - Local Privilege Escalation
CVE-2010-1183
Oracle Solaris - Arbitrary File Write via Symlink Attack on /tmp/CLEANUP
CVE-2010-0439
Chip Salzenberg Deliver - Symlink Attack
CVE-2010-0792
fcron < 3.0.5 - Arbitrary File Read via Symlink Attack
CVE-2010-0156
Puppet 0.24.0-0.24.8 and 0.25.0-0.25.1 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2010-0789
Fusermount <2.7.5, <2.8.2 - Local Privilege Escalation
CVE-2010-0788
ncpfs 2.2.6 - Symlink Attack via ncpmount and ncpumount
CVE-2010-0787
Samba <3.4.5 - Privilege Escalation
CVE-2010-0424
cronie < 1.4.4 - Denial of Service via Symlink Attack on Temporary File
CVE-2010-0118
Bournal < 1.4.1 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2009-1143 HIGH
VMware open-vm-tools 2009.03.18-154848 - Symlink Attack via Realpath Race Condition in mount.vmhgfs
CVSS 7.0
CVE-2009-1142 MEDIUM
VMware open-vm-tools 2009.03.18-154848 - Privilege Escalation via Symlink Attack on /tmp Files
CVSS 6.7
CVE-2009-0035 MEDIUM
alsa-utils <1.0.19 - Local File Overwrite
CVSS 5.5
CVE-2009-5023
fail2ban < 0.8.5 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2009-5082
GNU groff 1.20.1 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2009-5081
groff < 1.21 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2009-5080
groff < 1.21 - Arbitrary File Write via Symlink Attack on Temporary Directory
CVE-2009-5079
groff < 1.21 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2009-5044
Apple Mac OS X < 10.10.4 - Symlink Following
CVE-2009-5007
Cisco AnyConnect SSL VPN Trial Client - Arbitrary File Overwrite via Symlink Attack
CVE-2009-1299
PulseAudio 0.9.10 and 0.9.19 - Arbitrary File Ownership and Permissions Change via Symlink Attack
Details
Vulnerabilities 1,527
Exploit Likelihood Medium