CWE-59
1,516 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,516)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Broadcom GnuNetapp+1 more6Binutils Brocade Fabric Operating System FirmwareCloud Backup+3 moreDec 3, 2025 Mar 26, 2021 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a...Show more |
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacke...Show more |
2Fedoraproject Gnome2Fedora Gnome AutoarNov 21, 2024 Mar 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink i...Show more |
4Broadcom DebianFedoraproject+1 more4Brocade Fabric Operating System Firmware Debian LinuxFedora+1 moreNov 21, 2024 Mar 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlin...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Nov 21, 2024 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Update Stack Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreFeb 24, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 <p>An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who su...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreNov 21, 2024 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows User Profile Service Elevation of Privilege Vulnerability |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Nov 21, 2024 Mar 11, 2021 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Windows Update Service Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreNov 21, 2024 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Installer Elevation of Privilege Vulnerability |
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187...Show more |
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files). |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreNov 21, 2024 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause j...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Nov 21, 2024 Feb 25, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Windows Mobile Device Management Information Disclosure Vulnerability |
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory. |
2Avahi Debian2Avahi Debian LinuxNov 21, 2024 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via...Show more |
2Debian Mumble2Debian Linux MumbleNov 21, 2024 Feb 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text. |
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Se...Show more |
2Google Microsoft2Chrome Edge ChromiumNov 21, 2024 Feb 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. |
2Google Microsoft2Chrome Edge ChromiumNov 21, 2024 Feb 9, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. |
Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file. |