CWE-59
1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have alr...Show more |
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. |
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 a...Show more |
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx. |
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS. |
1Tanium 2Endpoint Configuration Toolset Solution Patch Endpoint ToolsJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. |
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. |
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools. |
Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Access ('Link Following') vulnerability in the Installer and Service. A low privileged attacker with loc...Show more |
Tanium addressed an improper link resolution before file access vulnerability in Enforce. |
Tanium addressed a documentation issue in Engage. |
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks...Show more |
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slo...Show more |
1Yottamaster 3Dm200 Firmware Dm2 FirmwareDm3 FirmwareJun 17, 2026 Feb 3, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior...Show more |
The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive t...Show more |
Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem contents, giving an attacker with physical access read‑only access to system files. |
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk. |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Jan 29, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete...Show more |
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatc...Show more |
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A mal...Show more |