CWE-61

High likelihood

UNIX Symbolic Link (Symlink) Following

Parent: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

125 vulnerabilities with CWE-61
CVE-2024-44132 HIGH
Apple Macos < 15.0 - Symlink Following
CVSS 8.8
CVE-2024-45310 LOW
runc <1.2.0-rc2 - Privilege Escalation
CVSS 3.6
CVE-2024-39578 MEDIUM
Dell Powerscale Onefs < 9.7.1.2 - Symlink Following
CVSS 6.3
CVE-2024-42367 MEDIUM
Aiohttp < 3.10.2 - Path Traversal
CVSS 4.8
CVE-2024-27872 MEDIUM
macOS Sonoma <14.6 - Info Disclosure
CVSS 5.5
CVE-2024-28189 CRITICAL
Judge0 <1.13.1 - Privilege Escalation
CVSS 10.0
CVE-2024-28185 CRITICAL
Judge0 - Code Injection
CVSS 10.0
CVE-2024-22014 HIGH
360 Total Security Antivirus <11.0.0.1061 - Privilege Escalation
CVSS 8.8
CVE-2024-25953 MEDIUM
Dell Powerscale Onefs < 9.4.0.16 - Symlink Following
CVSS 6.0
CVE-2024-25952 MEDIUM
Dell Powerscale Onefs < 9.3.0 - Symlink Following
CVSS 6.0
CVE-2024-1933 HIGH
TeamViewer <15.52 - Privilege Escalation
CVSS 7.1
CVE-2024-23285 MEDIUM
Apple Macos < 14.4 - Symlink Following
CVSS 5.5
CVE-2023-20093 MEDIUM
Cisco TelePresence CE - Privilege Escalation
CVSS 4.4
CVE-2023-20092 MEDIUM
Cisco TelePresence CE - Privilege Escalation
CVSS 4.4
CVE-2023-20091 MEDIUM
Cisco TelePresence CE - Privilege Escalation
CVSS 5.1
CVE-2023-41969 HIGH
Win ZApp <4.3.0 - Info Disclosure
CVSS 7.3
CVE-2023-39246 MEDIUM
Dell Endpoint Security Suite Enterprise < 11.8.1 - Symlink Following
CVSS 4.6
CVE-2023-37460 HIGH
Codehaus-plexus Plexus-archiver < 4.8.0 - Path Traversal
CVSS 8.1
CVE-2022-3592 MEDIUM
Samba - Path Traversal
CVSS 6.5
CVE-2022-31036 MEDIUM
Argo CD <v1.3.0 - Info Disclosure
CVSS 4.3
CVE-2022-24904 MEDIUM
Argoproj Argo CD < 2.1.15 - Symlink Following
CVSS 4.3
CVE-2021-4287 MEDIUM
ReFirm Labs binwalk <2.3.2 - Symlink Following
CVSS 5.0
CVE-2021-1612 MEDIUM
Cisco Sd-wan < 17.3.4 - Symlink Following
CVSS 5.5
CVE-2021-39135 HIGH
Npmjs Arborist < 2.8.2 - Symlink Following
CVSS 8.2
CVE-2021-39134 HIGH
@npmcli/arborist - Info Disclosure
CVSS 8.2
Details
Vulnerabilities 125
Exploit Likelihood High