CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 47 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-4184 | Med | 0.36 | 5.5 | 0.01 | Dec 10, 2019 | Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks | ||
| CVE-2019-3750 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2019 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to… | ||
| CVE-2019-3749 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2019 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the… | ||
| CVE-2019-17445 | Med | 0.36 | 5.5 | 0.00 | Nov 22, 2019 | An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following. | ||
| CVE-2011-2924 | Med | 0.36 | 5.5 | 0.00 | Nov 19, 2019 | foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible… | ||
| CVE-2011-2923 | Med | 0.36 | 5.5 | 0.00 | Nov 19, 2019 | foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible… | ||
| CVE-2010-4817 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2019 | pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. | ||
| CVE-2011-5271 | Med | 0.36 | 5.5 | 0.00 | Nov 12, 2019 | Pacemaker before 1.1.6 configure script creates temporary files insecurely | ||
| CVE-2009-0035 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2019 | alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts. | ||
| CVE-2019-18645 | Med | 0.36 | 5.5 | 0.00 | Oct 31, 2019 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories. | ||
| CVE-2019-1270 | Med | 0.36 | 5.5 | 0.01 | Sep 11, 2019 | An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1074 | Med | 0.36 | 5.5 | 0.02 | Jul 15, 2019 | An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could potentially access unauthorized information. The… | ||
| CVE-2019-11879 | Med | 0.36 | 5.5 | 0.01 | May 10, 2019 | The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore… | ||
| CVE-2019-1002101 | Med | 0.36 | 6.4 | 0.13 | Apr 1, 2019 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is… | ||
| CVE-2014-4150 | Med | 0.36 | 5.5 | 0.00 | Jul 20, 2018 | The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp. | ||
| CVE-2014-0243 | Med | 0.36 | 5.5 | 0.01 | Jul 19, 2018 | Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job. | ||
| CVE-2018-4112 | Med | 0.36 | 5.5 | 0.02 | Apr 3, 2018 | An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling. | ||
| CVE-2014-2312 | Med | 0.36 | 5.5 | 0.00 | Mar 26, 2018 | The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid. | ||
| CVE-2017-18188 | Med | 0.36 | 5.5 | 0.00 | Feb 14, 2018 | OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run. | ||
| CVE-2014-4996 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2018 | lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}. |
- risk 0.36cvss 5.5epss 0.01
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
- risk 0.36cvss 5.5epss 0.00
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to…
- risk 0.36cvss 5.5epss 0.00
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
- risk 0.36cvss 5.5epss 0.00
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…
- risk 0.36cvss 5.5epss 0.00
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…
- risk 0.36cvss 5.5epss 0.00
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
- risk 0.36cvss 5.5epss 0.00
Pacemaker before 1.1.6 configure script creates temporary files insecurely
- risk 0.36cvss 5.5epss 0.00
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
- risk 0.36cvss 5.5epss 0.00
The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
- risk 0.36cvss 5.5epss 0.02
An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could potentially access unauthorized information. The…
- risk 0.36cvss 5.5epss 0.01
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore…
- risk 0.36cvss 6.4epss 0.13
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is…
- risk 0.36cvss 5.5epss 0.00
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.
- risk 0.36cvss 5.5epss 0.01
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
- risk 0.36cvss 5.5epss 0.02
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.
- risk 0.36cvss 5.5epss 0.00
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.
- risk 0.36cvss 5.5epss 0.00
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.
- risk 0.36cvss 5.5epss 0.00
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.