← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sympa
1Sympa
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function,...Show more
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vulnerability.Show less
1Gnu
1Ibackup
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
1Freeradius
1Freeradius
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) t...Show more
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct.Show less
1Debian
1Feta
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/feta.avail.$USER temporary files.
1Debian
1Xsabre
Apr 23, 2026
Oct 3, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attack on unspecified .tmp files.
1Jasper Project
1Jasper
Apr 23, 2026
Oct 2, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file,...Show more
Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jasper to exit. NOTE: this was originally reported as a symlink issue, but this was incorrect. NOTE: some vendors dispute the severity of this issue, but it satisfies CVE's requirements for inclusion.Show less
1Redhat
1Cman
Apr 23, 2026
Sep 29, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
1Redhat
2Fedora
Initscripts
Apr 23, 2026
Sep 29, 2008
N/A· v4
N/A· v3
4.7 MEDIUM· v2
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
1Emacspeak Inc
1Emacspeak
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
6.6 MEDIUM· v2
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.
2Openswan
Xelerance
2Openswan
Openswan
Apr 23, 2026
Sep 24, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.ol...Show more
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.Show less
1Nooms
1Nooms
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the g_site_url parameter.
1Python Software Foundation
1Python
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be c...Show more
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.Show less
1Joomla
1Joomla
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.
4Canonical
DebianMysql+1 more
4Debian Linux
MysqlMysql+1 more
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pa...Show more
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.Show less
1Stephenjungels
1Plait
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
plaiter in Plait before 1.6 allows local users to overwrite arbitrary files via a symlink attack on (1) cut.$$, (2) head.$$, (3) awk.$$, and (4) ps.$$ temporary files in /tmp/.
1Hp
1Openvms
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.
1R Foundation
1R
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
1Debian
1Citadel Server
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
1Ampache
1Ampache
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.
1Debian
1Honeyd Common
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.