CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,754)
page 51 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-21269 | Med | 0.36 | 5.5 | 0.00 | Oct 27, 2020 | checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink. | ||
| CVE-2017-18925 | Med | 0.36 | 5.5 | 0.00 | Oct 26, 2020 | opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack. | ||
| CVE-2020-25289 | Med | 0.36 | 5.5 | 0.00 | Sep 13, 2020 | The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions). | ||
| CVE-2020-7325 | Med | 0.36 | 5.5 | 0.00 | Sep 9, 2020 | Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file. | ||
| CVE-2020-24332 | Med | 0.36 | 5.5 | 0.01 | Aug 13, 2020 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack. | ||
| CVE-2020-0779 | Med | 0.36 | 5.5 | 0.01 | Mar 12, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843. | ||
| CVE-2012-6114 | Med | 0.36 | 5.5 | 0.00 | Jan 28, 2020 | The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort. | ||
| CVE-2020-0616 | Med | 0.36 | 5.5 | 0.02 | Jan 14, 2020 | A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. | ||
| CVE-2019-8789 | Med | 0.36 | 5.5 | 0.01 | Dec 18, 2019 | A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information. | ||
| CVE-2019-8568 | Med | 0.36 | 5.5 | 0.00 | Dec 18, 2019 | A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system. | ||
| CVE-2013-4184 | Med | 0.36 | 5.5 | 0.01 | Dec 10, 2019 | Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks | ||
| CVE-2019-3750 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2019 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to… | ||
| CVE-2019-3749 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2019 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the… | ||
| CVE-2019-17445 | Med | 0.36 | 5.5 | 0.00 | Nov 22, 2019 | An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following. | ||
| CVE-2011-2924 | Med | 0.36 | 5.5 | 0.00 | Nov 19, 2019 | foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible… | ||
| CVE-2011-2923 | Med | 0.36 | 5.5 | 0.00 | Nov 19, 2019 | foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible… | ||
| CVE-2010-4817 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2019 | pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. | ||
| CVE-2011-5271 | Med | 0.36 | 5.5 | 0.00 | Nov 12, 2019 | Pacemaker before 1.1.6 configure script creates temporary files insecurely | ||
| CVE-2009-0035 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2019 | alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts. | ||
| CVE-2019-18645 | Med | 0.36 | 5.5 | 0.00 | Oct 31, 2019 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories. |
- risk 0.36cvss 5.5epss 0.00
checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink.
- risk 0.36cvss 5.5epss 0.00
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.
- risk 0.36cvss 5.5epss 0.00
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
- risk 0.36cvss 5.5epss 0.00
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
- risk 0.36cvss 5.5epss 0.00
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
- risk 0.36cvss 5.5epss 0.02
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
- risk 0.36cvss 5.5epss 0.01
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.
- risk 0.36cvss 5.5epss 0.00
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system.
- risk 0.36cvss 5.5epss 0.01
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
- risk 0.36cvss 5.5epss 0.00
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to…
- risk 0.36cvss 5.5epss 0.00
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
- risk 0.36cvss 5.5epss 0.00
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…
- risk 0.36cvss 5.5epss 0.00
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…
- risk 0.36cvss 5.5epss 0.00
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
- risk 0.36cvss 5.5epss 0.00
Pacemaker before 1.1.6 configure script creates temporary files insecurely
- risk 0.36cvss 5.5epss 0.00
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
- risk 0.36cvss 5.5epss 0.00
The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.