VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 50 of 88
  • CVE-2012-6114MedJan 28, 2020
    risk 0.36cvss 5.5epss 0.00

    The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.

  • CVE-2020-0616MedJan 14, 2020
    risk 0.36cvss 5.5epss 0.02

    A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

  • CVE-2019-8789MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.01

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.

  • CVE-2019-8568MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system.

  • CVE-2013-4184MedDec 10, 2019
    risk 0.36cvss 5.5epss 0.01

    Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

  • CVE-2019-3750MedDec 3, 2019
    risk 0.36cvss 5.5epss 0.00

    Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to…

  • CVE-2019-3749MedDec 3, 2019
    risk 0.36cvss 5.5epss 0.00

    Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the…

  • CVE-2019-17445MedNov 22, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.

  • CVE-2011-2924MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…

  • CVE-2011-2923MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…

  • CVE-2010-4817MedNov 13, 2019
    risk 0.36cvss 5.5epss 0.00

    pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

  • CVE-2011-5271MedNov 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Pacemaker before 1.1.6 configure script creates temporary files insecurely

  • CVE-2009-0035MedNov 9, 2019
    risk 0.36cvss 5.5epss 0.00

    alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.

  • CVE-2019-18645MedOct 31, 2019
    risk 0.36cvss 5.5epss 0.00

    The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.

  • CVE-2019-1270MedSep 11, 2019
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.

  • CVE-2019-1074MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.02

    An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could potentially access unauthorized information. The…

  • CVE-2019-11879MedMay 10, 2019
    risk 0.36cvss 5.5epss 0.01

    The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore…

  • CVE-2019-1002101MedApr 1, 2019
    risk 0.36cvss 6.4epss 0.13

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is…

  • CVE-2014-4150MedJul 20, 2018
    risk 0.36cvss 5.5epss 0.00

    The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.

  • CVE-2018-4112MedApr 3, 2018
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.