CWE-59
1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 13, 2026 Apr 2, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in th...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 13, 2026 Mar 23, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy,...Show more |
1Apple 3Iphone Os Mac Os XWatchosMay 13, 2026 Feb 20, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "libarchive" component, which allows local users...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 13, 2026 Feb 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" compon...Show more |
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. |
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox. |
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers u...Show more |
3Mariadb OraclePercona4Mariadb MysqlPercona Server+1 moreMay 6, 2026 Dec 13, 2016 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster befo...Show more |
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10,...Show more |
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps el...Show more |
2Fedoraproject Redhat2Ansible FedoraMay 6, 2026 Jun 3, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-scrip...Show more |
2Debian Tardiff Project2Debian Linux TardiffMay 6, 2026 May 6, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory. |
2Fedoraproject Zarafa2Fedora Zarafa Collaboration PlatformMay 6, 2026 Jan 11, 2016 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*. |
2Gummi Project Opensuse3Gummi LeapOpensuseMay 6, 2026 Jan 8, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the f...Show more |
1Redhat 5Automatic Bug Reporting Tool Enterprise Linux DesktopEnterprise Linux Hpc Node+2 moreMay 6, 2026 Dec 7, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated b...Show more |
1Redhat 5Automatic Bug Reporting Tool Enterprise Linux DesktopEnterprise Linux Hpc Node+2 moreMay 6, 2026 Dec 7, 2015 N/A· v4 N/A· v3 3.6 LOW· v2 The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created direc...Show more |
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map. |
2Apport Project Canonical2Apport Ubuntu LinuxMay 6, 2026 Oct 1, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log. |
2Canonical Linuxcontainers2Lxc Ubuntu LinuxMay 6, 2026 Oct 1, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source. |
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root pa...Show more |