CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,532 vulnerabilities with CWE-59
CVE-2008-0806
wyrd 1.4.3b - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-0163
Linux kernel 2.6 - Unauthenticated Resource Access via Symlink Attack in /proc
CVE-2008-0732
Apache Geronimo - Improper Link Resolution Before File Access via chown Operation
CVE-2008-0665
Website META Language 2.0.11 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-0666
Website META Language 2.0.11 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-0613
XOOPS 2.0.18 - Open Redirect via xoops_redirect Parameter
CVE-2008-0525
PatchLink Update & Novell ZENworks Patch Management - Arbitrary File Truncation & Code Execution via Symlink Attacks
CVE-2007-5495
setroubleshoot 2.0.5 - Arbitrary File Overwrite via Symlink Attack on sealert.log
CVE-2007-5664
IBM DB2 Universal Database - Arbitrary File Overwrite via Symlink Attack on Initialization Files
CVE-2007-4998
Linux Kernel - Arbitrary File Overwrite via Symlink Attack in cp with Preserve Symlinks Option
CVE-2007-6692
Menalto Gallery <2.2.4 - Open Redirect
CVE-2007-6595
ClamAV 0.92 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2007-6208
Claws Mail Tools - Local Privilege Escalation
CVE-2007-6061
Audacity 1.3.2 - Denial of Service and Arbitrary File Deletion via Symlink Attack
CVE-2007-5940
TeXLive 2007 - Arbitrary File Write and Code Execution via Symlink Attack on feynmf$$.pl Temporary File
CVE-2007-3921
gforge 3.1 and 4.5.14 - Arbitrary File Truncation via Symlink Attack
CVE-2007-4129
CoolKey 1.1.0 - Privilege Escalation
CVE-2007-5839
BitchX 1.1a - Local Privilege Escalation
CVE-2007-5805
IBM AIX - Local Privilege Escalation
CVE-2007-5718
vobcopy 0.5.14 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2007-5695
SiteBar 3.3.8 - Open Redirect via Forward Parameter
CVE-2007-3919
Xen <= 3.1 - Arbitrary File Truncation via Symlink Attack on /tmp/xenq-shm
CVE-2007-5200
Opensuse - Symlink Following
CVE-2007-5437
CA eTrust ITM 8.1 - Open Redirect via HTTP URL on Port 6689
CVE-2007-5377
Tramp 2.1.10 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
Details
Vulnerabilities
1,532
Exploit Likelihood
Medium