← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kegel
1Winetricks
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.
1Apple
1Cups
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary fi...Show more
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.Show less
1Microsoft
3Windows 2000
Windows 95Windows 98
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
7.6 HIGH· v2
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a m...Show more
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable.Show less
1Nokia
16131 Nfc
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
2.6 LOW· v2
The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r...Show more
The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r), and . (dot) characters, which allows remote attackers to trick a user into loading an arbitrary URI via a crafted NDEF tag, as demonstrated by (1) an http: URI for a malicious web site, (2) a tel: URI for a premium-rate telephone number, and (3) an sms: URI that triggers purchase of a ringtone.Show less
1Sun
1Snmp Management Agent
Apr 23, 2026
Dec 29, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.
1Pdfjam
1Pdfjam
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup files with a predictable name, which allows local users to overwrite arbitrary files via a symlink attack.
1Netcat
1Netcat
Apr 23, 2026
Dec 26, 2008
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to mod...Show more
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.Show less
1Verlihub Project
1Verlihub
Apr 23, 2026
Dec 22, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp tempo...Show more
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file.Show less
1Gpsdrive
1Gpsdrive
Apr 23, 2026
Dec 22, 2008
N/A· v4
N/A· v3
7.6 HIGH· v2
src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary file, a different vector than CVE-2008-...Show more
src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary file, a different vector than CVE-2008-4959 and CVE-2008-5380.Show less
1Gpsdrive
1Gpsdrive
Apr 23, 2026
Dec 22, 2008
N/A· v4
N/A· v3
6.2 MEDIUM· v2
gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/gpsdrivepos temporary file, related to (1) examples/gpssmswatch and (2)...Show more
gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/gpsdrivepos temporary file, related to (1) examples/gpssmswatch and (2) src/splash.c, different vectors than CVE-2008-4959 and CVE-2008-5380.Show less
1Debian
1Shadow
Apr 23, 2026
Dec 9, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (...Show more
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.Show less
1Gpsdrive
1Gpsdrive
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, rel...Show more
gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, related to the (1) geo-code and (2) geo-nearest scripts, different vectors than CVE-2008-4959.Show less
1Oliver Gorwits
1Netdisco Mibs Installer
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-downloa...Show more
netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts.Show less
1Lehrstuhl Fur Mikrobiologie
1Arb
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
arb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary file.
1Apple
1Cups
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
1Crip
1Crip
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
editcomment in crip 3.7 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.tag.tmp temporary file.
1Cmus
1Cmus
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file.
1Matthias Klose
1Bash Doc
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh, (2) aliasconv.bash, and (3) cshtobash scripts.
1Bacula
1Bacula
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.
1Jonas Smedegaard
1Sdm Terminal
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
sdm-login in sdm-terminal 0.4.0b allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sdm.autologin.once temporary file.