← Back
CWE-59

1,700 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,700)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Claroline
1Claroline
Apr 23, 2026
Jul 22, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
1Joomla
1Joomla
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
1Debian
1Projectl
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, which allows local users to overwrite arbitrary files via a symlink attack.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
7.6 HIGH· v2
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a do...Show more
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.Show less
1Opensuse
1Opensuse
Apr 23, 2026
Jun 6, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
opensuse-updater in openSUSE 10.2 allows local users to access arbitrary files via a symlink attack.
1Selinux
1Setroubleshoot
Apr 23, 2026
May 23, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.
1Gforge
1Gforge
Apr 23, 2026
May 18, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictio...Show more
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.Show less
2Nzbget
Uudeview
2Nzbget
Uudeview
Apr 23, 2026
May 16, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam functi...Show more
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.Show less
1Blender
1Blender
Apr 23, 2026
Apr 28, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
1Debian
1Aptlinex
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.
1Gnu
2Emacs
Sccs
Apr 23, 2026
Apr 22, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
1Ibm
1Db2 Universal Database
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on...Show more
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.Show less
1Cecilia
1Cecilia
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
3.3 LOW· v2
lib/prefs.tcl in Cecilia 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the csvers temporary file.
1Sun
1Solaris
Apr 23, 2026
Apr 6, 2008
N/A· v4
N/A· v3
4.7 MEDIUM· v2
inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.
1Policyd Weight
1Policyd Weight
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
3.3 LOW· v2
policyd-weight 0.1.14 beta-16 and earlier allows local users to modify or delete arbitrary files via a symlink attack on temporary files that are used when creating a socket.
1Mozilla
2Firefox
Seamonkey
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.
1Axyl
1Axyl
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file.
1Dovecot
1Dovecot
Apr 23, 2026
Mar 6, 2008
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that...Show more
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.Show less
1Adobe
1Acrobat Reader
Apr 23, 2026
Mar 6, 2008
N/A· v4
N/A· v3
3.7 LOW· v2
acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.
1Freshmeat
1Xwine
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party i...Show more
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information.Show less