CWE-59
1,607 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code executi...Show more |
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allow...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Sep 21, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem. |
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is fol...Show more |
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions). |
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted...Show more |
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted...Show more |
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could...Show more |
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee f...Show more |
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulat...Show more |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
1Superantispyware 1Professional X Jun 17, 2026 Sep 1, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory ju...Show more |
1Trendmicro 4Apex One OfficescanWorry Free Business Security+1 moreJun 17, 2026 Sep 1, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Sep 1, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on th...Show more |
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file. |
3Canonical FedoraprojectTuxfamily3Chrony FedoraUbuntu LinuxJun 17, 2026 Aug 24, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writ...Show more |
3Canonical Net SnmpNetapp5Cloud Backup Net SnmpSmi S Provider+2 moreJun 17, 2026 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links. |
2Fedoraproject Trustedcomputinggroup2Fedora TrousersJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt exis...Show more |
1Checkpoint 1Zonealarm Anti Ransomware Jun 17, 2026 Aug 4, 2020 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiti...Show more |