← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Nano
Apr 29, 2026
Apr 16, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an...Show more
GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.Show less
1Sun
1Solaris
Apr 29, 2026
Mar 29, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.
1Chip Salzenberg
1Deliver
Apr 29, 2026
Mar 26, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.
1Pulseaudio
1Pulseaudio
Apr 29, 2026
Mar 18, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.
1Thibault Godouet
1Fcron
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on an unspecified file.
1Fwbuilder
1Firewall Builder
Apr 29, 2026
Mar 3, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Firewall Builder 3.0.4, 3.0.5, and 3.0.6, when running on Linux, allows local users to gain privileges via a symlink attack on an unspecified temporary file that is created by the iptables script.
1Puppet
1Puppet
Apr 29, 2026
Mar 3, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.a...Show more
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.Show less
1Fuse
1Fuse
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
1Ncpfs
1Ncpfs
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
4.4 MEDIUM· v2
ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.
1Samba
1Samba
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
4.4 MEDIUM· v2
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mo...Show more
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.Show less
2Fedorahosted
Paul Vixie
2Cronie
Vixie Cron
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a syml...Show more
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.Show less
1Becauseinter
1Bournal
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.
1Saini
1Videocache
Apr 23, 2026
Dec 29, 2009
N/A· v4
N/A· v3
3.3 LOW· v2
vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a symlink attack on /var/log/videocache/vccleaner.log.
3Canonical
FedoraprojectGnu
3Coreutils
FedoraUbuntu Linux
Apr 23, 2026
Dec 11, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
1Gforge
1Gforge
Apr 23, 2026
Dec 4, 2009
N/A· v4
N/A· v3
3.3 LOW· v2
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron...Show more
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.Show less
1Merkaartor
1Merkaartor
Apr 23, 2026
Dec 3, 2009
N/A· v4
N/A· v3
3.3 LOW· v2
Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.
2Mysql
Oracle
2Mysql
Mysql
Apr 23, 2026
Nov 30, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated w...Show more
MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.Show less
2Mysql
Oracle
2Mysql
Mysql
Apr 23, 2026
Nov 30, 2009
N/A· v4
N/A· v3
6.0 MEDIUM· v2
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass int...Show more
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.Show less
2Novell
Opensuse
2Opensuse
Suse Linux
Apr 23, 2026
Oct 23, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unsp...Show more
iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.Show less
1Postfix
1Postfix
Apr 23, 2026
Sep 21, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite...Show more
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.Show less