CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,578 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 7 of 32
- CVE-2010-2064HIGHCVSS 7.1EG 7.12019-10-29
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
- CVE-2010-2192LOWCVSS v2 1.9EG 1.92010-06-18
The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.
- CVE-2010-2431LOWCVSS v2 2.6EG 2.62010-06-22
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
- CVE-2010-2794LOWCVSS v2 3.3EG 3.32010-08-30
The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.
- CVE-2010-3095MEDIUMCVSS 4.7EG 4.72019-11-12
mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313.
- CVE-2010-3691LOWCVSS v2 3.3EG 3.32010-10-07
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
- CVE-2010-3847MEDIUMCVSS v2 6.9EG 6.92011-01-07
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via …
- CVE-2010-3879MEDIUMCVSS v2 5.8EG 5.82011-01-22
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different…
- CVE-2010-4173LOWCVSS v2 3.3EG 3.32010-11-22
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log.##### temporary file.
- CVE-2010-4226HIGHCVSS 7.2EG 7.22014-02-06
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
- CVE-2010-4337LOWCVSS v2 3.3EG 3.32011-01-14
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.
- CVE-2010-4817MEDIUMCVSS 5.5EG 5.52019-11-13
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
- CVE-2010-5105LOWCVSS v2 3.3EG 3.32014-04-27
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
- CVE-2011-0007LOWCVSS v2 3.3EG 3.32011-01-11
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is sent.
- CVE-2011-0012LOWCVSS v2 3.3EG 3.32011-04-18
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.
- CVE-2011-0402MEDIUMCVSS v2 6.8EG 6.82011-01-11
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
- CVE-2011-0441MEDIUMCVSS v2 6.3EG 6.32011-03-29
The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.
- CVE-2011-0460MEDIUMCVSS v2 6.3EG 6.32014-04-16
The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.
- CVE-2011-0461MEDIUMCVSS v2 6.3EG 6.32011-04-04
/etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/mtab.
- CVE-2011-0541LOWCVSS v2 3.3EG 3.32011-09-02
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
- CVE-2011-0702LOWCVSS v2 3.3EG 3.32011-02-14
The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file.
- CVE-2011-0727MEDIUMCVSS v2 6.9EG 6.92011-03-31
GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
- CVE-2011-0754MEDIUMCVSS v2 4.4EG 4.42011-02-02
The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross…
- CVE-2011-1004MEDIUMCVSS v2 6.3EG 6.32011-03-02
The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.
- CVE-2011-1031LOWCVSS v2 3.3EG 3.32011-02-14
The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to create arbitrary files via a symlink attack on a /tmp/feh_ temporary file, a different vulnerability than CVE-2011-0702.
- CVE-2011-1072LOWCVSS v2 3.3EG 3.32011-03-03
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a differ…
- CVE-2011-1073LOWCVSS v2 1.9EG 1.92011-03-04
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary …
- CVE-2011-1136MEDIUMCVSS 4.7EG 4.72019-11-14
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
- CVE-2011-1144LOWCVSS v2 3.3EG 3.32011-03-03
The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NO…
- CVE-2011-1384MEDIUMCVSS v2 4.0EG 4.02012-01-04
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrar…
- CVE-2011-1408HIGHCVSS 8.2EG 8.22019-10-29
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
- CVE-2011-1920LOWCVSS v2 3.3EG 3.32011-05-23
The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog…
- CVE-2011-2473MEDIUMCVSS v2 6.3EG 6.32011-06-09
The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a dif…
- CVE-2011-2533LOWCVSS v2 3.3EG 3.32011-06-22
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
- CVE-2011-2684MEDIUMCVSS 5.5EG 5.52017-10-23
foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write ove…
- CVE-2011-2722LOWCVSS v2 1.2EG 1.22012-05-25
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.
- CVE-2011-2765HIGHCVSS 7.5EG 7.52018-08-20
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
- CVE-2011-2923MEDIUMCVSS 5.5EG 5.52019-11-19
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by o…
- CVE-2011-2924MEDIUMCVSS 5.5EG 5.52019-11-19
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks b…
- CVE-2011-3153LOWCVSS v2 1.9EG 1.92014-03-06
dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc.
- CVE-2011-3154LOWCVSS v2 1.9EG 1.92014-04-17
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files,…
- CVE-2011-3204LOWCVSS v2 3.3EG 3.32011-09-06
hammerhead.cc in Hammerhead 2.1.4 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/hammer.log (aka the HH_LOG file) or (2) the REPORT_LOG file.
- CVE-2011-3351HIGHCVSS 7.1EG 7.12019-11-25
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrit…
- CVE-2011-3616MEDIUMCVSS v2 6.3EG 6.32011-11-04
The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.
- CVE-2011-3618HIGHCVSS 7.8EG 7.82019-11-12
atop: symlink attack possible due to insecure tempfile handling
- CVE-2011-3632HIGHCVSS 7.1EG 7.12019-11-26
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
- CVE-2011-4028LOWCVSS v2 1.2EG 1.22012-07-03
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
- CVE-2011-4060LOWCVSS v2 3.3EG 3.32011-10-18
The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, which allows local users to overwrite files…
- CVE-2011-4105LOWCVSS v2 1.9EG 1.92012-02-17
LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.
- CVE-2011-4116LOWCVSS 3.3EG 3.32020-01-31
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →