← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Policyd Weight
1Policyd Weight
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
3.3 LOW· v2
policyd-weight 0.1.14 beta-16 and earlier allows local users to modify or delete arbitrary files via a symlink attack on temporary files that are used when creating a socket.
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.
1Axyl
1Axyl
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file.
1Dovecot
1Dovecot
Apr 23, 2026
Mar 6, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that...Show more
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.Show less
1Adobe
1Acrobat Reader
Apr 23, 2026
Mar 6, 2008
N/A· v4
N/A· v3
3.7 LOW· v2
acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.
1Freshmeat
1Xwine
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party i...Show more
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information.Show less
2Gentoo
Rpath
2Linux
Rpath Linux
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same iss...Show more
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.Show less
2Bea Systems
Oracle
2Weblogic Portal
Weblogic Portal
Apr 23, 2026
Feb 21, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to s...Show more
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.Show less
1Paul Pelzl
1Wyrd
Apr 23, 2026
Feb 19, 2008
N/A· v4
N/A· v3
3.6 LOW· v2
wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.
1Apache
1Geronimo
Apr 23, 2026
Feb 12, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
1Linux
1Linux Kernel
Apr 23, 2026
Feb 12, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.
1Website Meta Language
1Website Meta Language
Apr 23, 2026
Feb 11, 2008
N/A· v4
N/A· v3
3.6 LOW· v2
Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_...Show more
Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c.Show less
1Website Meta Language
1Website Meta Language
Apr 23, 2026
Feb 11, 2008
N/A· v4
N/A· v3
3.6 LOW· v2
wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file.
1Xoops
1Xoops
Apr 23, 2026
Feb 6, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter.
1Linux
1Linux Kernel
Apr 23, 2026
Jan 31, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files th...Show more
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.Show less
2Lumension Security
Novell
2Patchlink Update
Zenworks Patch Management Update Agent
Apr 23, 2026
Jan 31, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symli...Show more
PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.Show less
1Menalto
1Gallery
Apr 23, 2026
Jan 17, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.
1Clam Anti Virus
1Clamav
Apr 23, 2026
Dec 31, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode i...Show more
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.Show less
1Claws Mail
1Claws Mail Tools
Apr 23, 2026
Dec 4, 2007
N/A· v4
N/A· v3
3.6 LOW· v2
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
1Audacityteam
1Audacity
Apr 23, 2026
Nov 20, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the d...Show more
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.Show less