CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,527 vulnerabilities with CWE-59
CVE-2009-4664
Firewall Builder <3.0.7 - Privilege Escalation
CVE-2009-4454
VideoCache 1.9.2 - Local Privilege Escalation
CVE-2009-4135
GNU coreutils <8.1 - Privilege Escalation
CVE-2009-3304
GForge 4.5.14, 4.7 rc2, and 4.8.2 - Arbitrary File Overwrite via Symlink Attack on Authorized Keys
CVE-2009-4193
Merkaartor 0.14 - Local Info Disclosure
CVE-2009-4030
MySQL 5.1.x <5.1.41 - Privilege Escalation
CVE-2009-1297
SUSE Linux and openSUSE - Arbitrary File Write via Symlink Attack on Temporary File
CVE-2009-2939
Postfix 2.5.5 - Arbitrary File Write via Symlink Attack in postfix.postinst Script
CVE-2009-1867
Adobe AIR < 1.5.2 - Clickjacking via Link Selection or Dialog Completion
CVE-2009-1893
Red Hat dhcpd <3.0.1 - Local Privilege Escalation
CVE-2009-1962
xfig - Arbitrary File Read and Write via Symlink Attack on Temporary Files
CVE-2009-1753
Coccinelle 0.1.7 - Arbitrary File Overwrite via Symlink Attack
CVE-2009-1526
DirectAdmin < 1.33.4 - Unauthenticated Arbitrary File Write via Symlink Attack on Backup Temporary File
CVE-2009-1253
James Stone Tunapie 2.1 - Arbitrary File Overwrite via Symlink Attack
CVE-2009-0876
Sun xVM VirtualBox 2.0.0-2.1.4 - Privilege Escalation via Hardlink Attack
CVE-2009-0473
Rockwell Automation ControlLogix 1756-ENBT/A - Open Redirect
CVE-2009-0356
Mozilla Firefox <3.0.6 & SeaMonkey - XSS
CVE-2009-0416
SBLIM sblim-sfcb 1.3.2 - Local Privilege Escalation
CVE-2009-0347
Autonomy Ultraseek - Open Redirect via cs.html url Parameter
CVE-2009-0321
Apple Safari 3.2.1 - Denial of Service via Malformed HTTP URI Authority
CVE-2009-0313
winetricks <20081223 - Local Privilege Escalation
CVE-2009-0032
CUPS - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-7273 HIGH
Iceweasel-firegpg <0.6 - Info Disclosure
CVSS 7.8
CVE-2008-7247
MySQL <6.0.9-alpha - Privilege Escalation
CVE-2008-6762
WordPress - Open Redirect via Upgrade Backto Parameter
Details
Vulnerabilities 1,527
Exploit Likelihood Medium