CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,532 vulnerabilities with CWE-59
CVE-2007-5207
guilt 0.27 - Arbitrary File Overwrite via Symlink Attack on Temporary Log File
CVE-2007-3916
SKK Tools 1.2 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2007-4652
PHP < 5.2.4 - Local Symlink Bypass of open_basedir Restrictions via Session File
CVE-2007-4631
QGit up to 2pre1 - Arbitrary File Write via Symlink Attack on Predictable Temporary Files
CVE-2007-4224
KDE Konqueror 3.5.7 - URL Spoofing via setInterval
CVE-2007-3742
Safari < 3.0.2 - Phishing via IDN Homograph Spoofing
CVE-2007-3103
Fedora Core - Arbitrary File Permission Change via Symlink Attack on /tmp/.font-unix
CVE-2007-2978
eggblog < 3.1.0 - Session Fixation via PHPSESSID Parameter
CVE-2007-1027
IBM DB2 <9 FP2 - Local File Overwrite
CVE-2006-5851
OpenBase SQL < 10.0.1 - Arbitrary File Creation via Symlink Attack on /tmp/output
CVE-2006-1247
AIX 5.1.0-5.3.0 - Local Privilege Escalation
CVE-2005-2527
Java < 1.4.2 Release 2 - Arbitrary File Creation via Temporary Directory Race Condition
CVE-2005-2714
Mac OS X <10.3.9, <10.4.5 - Local Info Disclosure
CVE-2005-3126
Antiword <0.35 - Local File Overwrite
CVE-2005-3349
GNU Gnump3d < 2.9.8 - Arbitrary File Modification via Symlink Attack on index.lok
CVE-2005-3011
texinfo <4.8 - Local Privilege Escalation
CVE-2005-1916 MEDIUM
ekg < 2005-06-05 - Arbitrary File Write via Symlink Attack on Temporary Files
CVSS 5.5
CVE-2005-1879 MEDIUM
LutelWall < 0.98 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVSS 5.5
CVE-2005-1880 MEDIUM
everybuddy < 0.4.3 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVSS 5.5
CVE-2005-0824 MEDIUM
mathopd < 1.5p5 and 1.6x < 1.6b6 BETA - Arbitrary File Overwrite via Symlink Attack on Dump Files
CVSS 5.5
CVE-2005-1111 MEDIUM
cpio <2.6 - Local Privilege Escalation
CVSS 4.7
CVE-2005-0004
MySQL < 4.0.23, 4.1.x < 4.1.10, 5.0.x < 5.0.3 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2005-0587 MEDIUM
Firefox < 1.0.1 and Mozilla < 1.7.6 - Arbitrary File Overwrite via .LNK File Download
CVSS 6.5
CVE-2004-0967
Trustix Secure Linux <2.1 - Local File Overwrite
CVE-2004-1901 MEDIUM
Portage < 2.0.50-r3 - Arbitrary File Overwrite via Hard Link Attack
CVSS 5.5
Details
Vulnerabilities 1,532
Exploit Likelihood Medium