CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,578 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 10 of 32
- CVE-2015-1038MEDIUMCVSS v2 5.8EG 5.82015-01-21
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
- CVE-2015-1130CRITICALCVSS 7.8EG 9.0⚠ KEV2015-04-10
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
- CVE-2015-1194MEDIUMCVSS v2 4.3EG 4.32015-01-21
pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
- CVE-2015-1196MEDIUMCVSS v2 4.3EG 4.32015-01-21
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
- CVE-2015-1377MEDIUMCVSS v2 4.9EG 4.92015-02-10
The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified file.
- CVE-2015-1869HIGHCVSS 7.8EG 7.82020-01-14
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
- CVE-2015-3147MEDIUMCVSS 6.5EG 6.52020-01-14
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on …
- CVE-2015-3149MEDIUMCVSS 5.5EG 5.52017-07-25
The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.
- CVE-2015-3156MEDIUMCVSS 5.5EG 5.52017-08-11
The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/config.py, write_config function in trove/guestagent/datas…
- CVE-2015-3211MEDIUMCVSS 5.5EG 5.52017-08-25
php-fpm allows local users to write to or create arbitrary files via a symlink attack.
- CVE-2015-3315HIGHCVSS 7.8EG 7.82017-06-26
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4…
- CVE-2015-5700MEDIUMCVSS 6.1EG 6.12017-08-25
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
- CVE-2015-5701MEDIUMCVSS 6.1EG 6.12017-08-25
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.
- CVE-2015-5705HIGHCVSS 7.5EG 7.52017-09-06
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
- CVE-2015-6240HIGHCVSS 7.8EG 7.82017-06-07
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
- CVE-2015-6566HIGHCVSS 8.4EG 8.42016-01-11
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
- CVE-2015-7529HIGHCVSS 7.8EG 7.82017-11-06
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosr…
- CVE-2015-7723HIGHCVSS 7.8EG 7.82017-06-07
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
- CVE-2015-7724HIGHCVSS 7.8EG 7.82017-06-07
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
- CVE-2015-7758LOWCVSS 3.3EG 3.32016-01-08
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demons…
- CVE-2015-8326MEDIUMCVSS 5.5EG 5.52017-06-07
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
- CVE-2015-8860HIGHCVSS 7.5EG 7.52017-01-23
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
- CVE-2016-10374MEDIUMCVSS 5.5EG 5.52017-05-17
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users …
- CVE-2016-1247HIGHCVSS 7.8EG 7.82016-11-29
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuil…
- CVE-2016-1255HIGHCVSS 7.8EG 7.82017-12-05
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, …
- CVE-2016-3096HIGHCVSS 7.8EG 7.82016-06-03
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived…
- CVE-2016-3108HIGHCVSS 7.1EG 7.12017-06-08
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
- CVE-2016-4679MEDIUMCVSS 5.5EG 5.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows r…
- CVE-2016-6253HIGHCVSS 7.8EG 7.82017-01-20
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
- CVE-2016-6664HIGHCVSS 7.0EG 7.02016-12-13
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6…
- CVE-2016-7490HIGHCVSS 7.8EG 7.82016-11-10
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.
- CVE-2016-7619MEDIUMCVSS 5.5EG 5.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "libarchive" component, which allows local users to write to arbitra…
- CVE-2016-8641HIGHCVSS 6.7EG 7.82018-08-01
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links befo…
- CVE-2016-9566HIGHCVSS 7.8EG 7.82016-12-15
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
- CVE-2016-9595HIGHCVSS 7.3EG 7.32018-07-27
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary …
- CVE-2016-9602HIGHCVSS 7.6EG 8.82018-04-26
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privile…
- CVE-2016-9774HIGHCVSS 7.8EG 7.82017-03-23
The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb…
- CVE-2017-1000115HIGHCVSS 7.5EG 7.52017-10-05
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
- CVE-2017-1000420HIGHCVSS 7.5EG 7.52018-01-02
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
- CVE-2017-1002101CRITICALCVSS 8.8EG 9.62018-03-13
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/direc…
- CVE-2017-12172MEDIUMCVSS 6.7EG 6.72017-11-22
PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run a…
- CVE-2017-12258MEDIUMCVSS 6.1EG 6.12017-10-05
A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack. The vulnerability exists because the affected software does not pr…
- CVE-2017-1301MEDIUMCVSS 5.5EG 5.52017-10-05
IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbol…
- CVE-2017-15097MEDIUMCVSS 6.5EG 6.72018-07-27
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
- CVE-2017-15111MEDIUMCVSS 5.5EG 5.52018-01-20
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
- CVE-2017-15357HIGHCVSS 7.4EG 7.42017-12-01
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
- CVE-2017-16611MEDIUMCVSS 5.5EG 5.52017-12-01
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
- CVE-2017-18078HIGHCVSS 7.8EG 7.82018-01-29
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vector…
- CVE-2017-18188MEDIUMCVSS 5.5EG 5.52018-02-14
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.
- CVE-2017-18925MEDIUMCVSS 5.5EG 5.52020-10-26
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →