CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,532 vulnerabilities with CWE-59
CVE-2008-4580
cman - Arbitrary File Modification via Symlink Attack on Temporary File
CVE-2008-4579
cman - Arbitrary File Write via Symlink Attack on apclog Temporary File
CVE-2008-4553
qemu 0.9.1-5 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-4477
mon 0.99.2 - Arbitrary File Write via Symlink Attack on test.alert.log
CVE-2008-4476
sympa 5.3.4 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-4475
ibackup 2.27 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-4474
freeradius 2.0.4 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-4440
feta 1.4.16 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-4406
xsabre - Arbitrary File Deletion and Overwrite via Symlink Attack on Temporary Files
CVE-2008-3521
JasPer 1.900.1 - Denial of Service via Temporary File Race Condition
CVE-2008-4192
cman 2.20080629 and 2.20080801 - Arbitrary File Write via Symlink Attack on /tmp/eglog
CVE-2008-3524
rc.sysinit <8.76.3-1 - Local File Deletion
CVE-2008-4191
Emacspeak 26 and 28 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-4190
Openswan <=2.4.12, 2.6.x<=2.6.16 - Arbitrary File Write and Code Execution via Symlink Attack
CVE-2008-4162
NooMS 1.1 - Open Redirect via g_site_url Parameter
CVE-2008-4108
Python 2.4.5 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-4104
Joomla! 1.5.0-1.5.6 - Open Redirect via Passed-in URL
CVE-2008-4098
Canonical Ubuntu Linux - Symlink Following
CVE-2008-4085
Plait < 1.6 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-3946
HP TCP/IP Services for OpenVMS 5.x - Info Disclosure
CVE-2008-3927
Tiger 3.2.2 - Local Privilege Escalation
CVE-2008-3928
honeyd_common - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-3929
Ampache 3.4.1 - Local Privilege Escalation
CVE-2008-3930
Citadel Server 7.37 - Local Privilege Escalation
CVE-2008-3931
R <2.7.2 - Local Privilege Escalation
Details
Vulnerabilities
1,532
Exploit Likelihood
Medium