← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Conectiva
Kirk Bauer
2Diskcheck
Linux
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.
1Qualcomm
1Eudora
Apr 16, 2026
Apr 28, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
1Perl
1Perl
Apr 16, 2026
Dec 31, 1999
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
1Microsoft
1Internet Explorer
Apr 16, 2026
Dec 8, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
1Microsoft
1Excel
Apr 16, 2026
Oct 1, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
1Freebsd
1Freebsd
Apr 16, 2026
Jun 16, 1998
N/A· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.