CWE-59
1,607 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause j...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Feb 25, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Windows Mobile Device Management Information Disclosure Vulnerability |
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory. |
2Avahi Debian2Avahi Debian LinuxJun 17, 2026 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via...Show more |
2Debian Mumble2Debian Linux MumbleJun 17, 2026 Feb 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text. |
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Se...Show more |
2Google Microsoft2Chrome Edge ChromiumJun 17, 2026 Feb 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. |
2Google Microsoft2Chrome Edge ChromiumJun 17, 2026 Feb 9, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. |
Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file. |
2Fedoraproject Gnome2Fedora Gnome AutoarJun 17, 2026 Feb 5, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink...Show more |
1Netapp 1Oncommand Unified Manager Jun 17, 2026 Jan 28, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink). |
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a...Show more |
1Ibm 1Security Identity Governance And Intelligence Jun 17, 2026 Jan 21, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or...Show more |
1Cisco 5Catalyst Sd Wan Manager Ios Xe Sd WanSd Wan Firmware+2 moreJun 17, 2026 Jan 20, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, s...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Jan 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. |
A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the a...Show more |
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks. |
3Fedoraproject NetappSudo Project4Fedora Hci Management NodeSolidfire+1 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This aff...Show more |
4Debian FedoraprojectNetapp+1 more6Cloud Backup Debian LinuxFedora+3 moreJun 17, 2026 Jan 12, 2021 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symli...Show more |
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access...Show more |