← Back
CWE-59

1,700 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,700)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cvsup
1Cvsup
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.
1Sun
1Patchpro
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."
1Sun
1Solaris Pc Netlink
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypa...Show more
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Sep 5, 2002
N/A· v4
5.5 MEDIUM· v3
4.6 MEDIUM· v2
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the targ...Show more
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.Show less
1Freebsd
1Point To Point Protocol Daemon
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
6.9 MEDIUM· v2
BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
1Blackberry
1Qnx Neutrino Real Time Operating System
Apr 16, 2026
Aug 12, 2002
N/A· v4
5.5 MEDIUM· v3
4.6 MEDIUM· v2
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3)...Show more
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.Show less
2Avaya
Kernel
7Cvlan
Integrated Management SuitInteractive Response+4 more
Apr 16, 2026
Dec 31, 2001
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script comm...Show more
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.Show less
1Fetchmail
1Fetchmail
Apr 16, 2026
Sep 6, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.
1Transsoft
1Broker Ftp Server
Apr 16, 2026
Jul 2, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
1Texasimperialsoftware
1Wftpd
Apr 16, 2026
Jul 1, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.
1Argosoft
1Ftp Server
Apr 16, 2026
Jul 1, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
2Apache
Debian
2Debian Linux
Http Server
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
3.3 LOW· v2
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
1Joseph Allen
1Joe
Apr 16, 2026
Jan 9, 2001
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.
1Hp
1Hp Ux
Apr 16, 2026
Dec 19, 2000
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab gene...Show more
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.Show less
2Conectiva
Kirk Bauer
2Diskcheck
Linux
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.
1Qualcomm
1Eudora
Apr 16, 2026
Apr 28, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
1Perl
1Perl
Apr 16, 2026
Dec 31, 1999
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.
1Microsoft
1Internet Explorer
Apr 16, 2026
Dec 8, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
1Microsoft
1Excel
Apr 16, 2026
Oct 1, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
1Freebsd
1Freebsd
Apr 16, 2026
Jun 16, 1998
N/A· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.