← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Exim
1Exim
Apr 29, 2026
Feb 2, 2011
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
1Libfuse Project
1Libfuse
Apr 29, 2026
Jan 22, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE file...Show more
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.Show less
1Jwilk
1Ocrodjvu
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
6.2 MEDIUM· v2
ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
1Gnu
1Gnash
Apr 29, 2026
Jan 14, 2011
N/A· v4
N/A· v3
3.3 LOW· v2
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recomm...Show more
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.Show less
1Debian
1Dpkg
Apr 29, 2026
Jan 11, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
1Troglobit
1Pimd
Apr 29, 2026
Jan 11, 2011
N/A· v4
N/A· v3
3.3 LOW· v2
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is sent.
1Gnu
1Glibc
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
6.9 MEDIUM· v2
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to g...Show more
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.Show less
1Openfabrics
1Libsdp
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log.##### te...Show more
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log.##### temporary file.Show less
1Openfabrics
1Enterprise Distribution
Apr 29, 2026
Oct 26, 2010
N/A· v4
N/A· v3
6.3 MEDIUM· v2
openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file.
1Cisco
1Anyconnect Ssl Vpn
Apr 29, 2026
Oct 14, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files.
1Apereo
1Phpcas
Apr 29, 2026
Oct 7, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
1Redhat
1Spice Xpi
Apr 29, 2026
Aug 30, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.
1Gnu
1Gv
Apr 29, 2026
Jul 22, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
1Canonical
1Ubuntu Linux
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary f...Show more
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.Show less
1Apple
1Cups
Apr 29, 2026
Jun 22, 2010
N/A· v4
N/A· v3
2.6 LOW· v2
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file...Show more
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.Show less
1Vincent Fourmond
1Pmount
Apr 29, 2026
Jun 18, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Jun 17, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At...Show more
Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder.Show less
1Emesene
1Emesene
Apr 29, 2026
Jun 7, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.
1Wolfram Research
1Mathematica
Apr 29, 2026
May 24, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.
2Mysql
Oracle
2Mysql
Mysql
Apr 29, 2026
May 21, 2010
N/A· v4
N/A· v3
3.6 LOW· v2
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and C...Show more
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.Show less