← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Systemd Project
1Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
5.0 MEDIUM· v3
3.3 LOW· v2
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
1Redhat
1Storage Server
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
3.6 LOW· v2
Red Hat Storage 2.0 allows local users to overwrite arbitrary files via a symlink attack on the (1) e, (2) local-bricks.list, (3) bricks.err, or (4) limits.conf files in /tmp.
2Debian
Marc Vertes
2Txt2man
Txt2man
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.
1Phusion
1Passenger
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
4.4 MEDIUM· v2
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a pre...Show more
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.Show less
3Jeff Ortel
OpensuseRedhat
3Enterprise Linux
OpensuseSuds
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
1.2 LOW· v2
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
1Gnome
1Gnome Display Manager
Apr 29, 2026
Sep 10, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
1Bestpractical
1Rt
Apr 29, 2026
Aug 23, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.
2Fedoraproject
Pypa
2Fedora
Pip
Apr 29, 2026
Aug 17, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
1Redhat
2Enterprise Linux
Jboss Enterprise Web Server
Apr 29, 2026
Jul 9, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the...Show more
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.Show less
1Google
1Chrome Os
Apr 29, 2026
Apr 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE envi...Show more
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.Show less
1Oracle
1Support Tools
Apr 29, 2026
Mar 18, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp.
1Fusionforge
1Fusionforge
Apr 29, 2026
Mar 14, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-specific/ssh_dump_update.pl, (6) deb-specific/user_dump_update.pl, (7) plugi...Show more
(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-specific/ssh_dump_update.pl, (6) deb-specific/user_dump_update.pl, (7) plugins/scmbzr/common/BzrPlugin.class.php, (8) plugins/scmcvs/common/CVSPlugin.class.php, (9) plugins/scmcvs/cronjobs/cvs.php, (10) plugins/scmcvs/cronjobs/ssh_create.php, (11) plugins/scmgit/common/GitPlugin.class.php, (12) plugins/scmsvn/common/SVNPlugin.class.php, (13) plugins/wiki/cronjobs/create_groups.php, (14) utils/cvs1/cvscreate.sh, and (15) utils/include.pl in FusionForge 5.0, 5.1, and 5.2 allows local users to change arbitrary file permissions, obtain sensitive information, and have other unspecified impacts via a (1) symlink or (2) hard link attack on certain files.Show less
1Openstack
2Essex
Folsom
Apr 30, 2026
Mar 8, 2013
N/A· v4
8.8 HIGH· v3
4.4 MEDIUM· v2
A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the...Show more
A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the system, potentially leading to system compromise or data corruption.Show less
2Hp
Redhat
2Enterprise Linux
Linux Imaging And Printing Project
Apr 29, 2026
Mar 6, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /...Show more
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.Show less
1Google
1Android Debug Bridge
Apr 29, 2026
Feb 14, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.
1Centrify
2Centrify Deployment Manager
Centrify Suite
Apr 29, 2026
Jan 4, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, or (2) overwrite arbi...Show more
Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, or (2) overwrite arbitrary files and consequently gain privileges via a symlink attack on the centrify.cmd.0 temporary file.Show less
1Ibm
2Advanced Settings Utility
Bootable Media Creator
Apr 29, 2026
Dec 19, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on...Show more
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.Show less
1Bryce Harrington
1Xdiagnose
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
welcome.py in xdiagnose before 2.5.2ubuntu0.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
1Opencryptoki Project
1Opencryptoki
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
6.2 MEDIUM· v2
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.
1Frii
1Proc\
Apr 29, 2026
Oct 7, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY information caching is enabled, allows local users to overwrite arbitrary files via a symlink attack on /tmp/TTYDEVS.