CWE-59
1,607 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user s...Show more |
A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files. |
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to...Show more |
1Microsoft 6Visual Studio Visual Studio 2017Visual Studio 2019+3 moreJun 17, 2026 Apr 13, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability |
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin director...Show more |
2Fedoraproject Gnome2Fedora File RollerJun 17, 2026 Apr 7, 2021 N/A· v4 3.9 LOW· v3 2.6 LOW· v2 fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in cer...Show more |
5Apache EclipseFedoraproject+2 more23Autovue For Agile Product Lifecycle Management Banking ApisBanking Digital Experience+20 moreJun 17, 2026 Apr 1, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadverte...Show more |
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp. |
This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Security 20.8.2429 (Build 20.8.5653.561). An attacker must first obtain the ability to execute low-priv...Show more |
4Broadcom GnuNetapp+1 more6Binutils Brocade Fabric Operating System FirmwareCloud Backup+3 moreJun 17, 2026 Mar 26, 2021 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a...Show more |
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacke...Show more |
2Fedoraproject Gnome2Fedora Gnome AutoarJun 17, 2026 Mar 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink i...Show more |
4Broadcom DebianFedoraproject+1 more4Brocade Fabric Operating System Firmware Debian LinuxFedora+1 moreJun 17, 2026 Mar 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlin...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows Update Stack Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 <p>An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who su...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows User Profile Service Elevation of Privilege Vulnerability |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Mar 11, 2021 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Windows Update Service Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Mar 11, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Installer Elevation of Privilege Vulnerability |
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187...Show more |
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files). |