CWE-59
1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects:...Show more |
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects:...Show more |
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jan 21, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeB...Show more |
2Opensuse Squid Analysis Report Generator Project3Backports Sle LeapSquid Analysis Report GeneratorJun 17, 2026 Jan 21, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an exis...Show more |
1Microsoft 9Windows 10 1709 Windows 10 1803Windows 10 1809+6 moreJun 17, 2026 Jan 14, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Noti...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jan 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. |
1Redhat 7Automatic Bug Reporting Tool Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jan 14, 2020 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a...Show more |
1Redhat 1Automatic Bug Reporting Tool Nov 21, 2024 Jan 14, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file. |
1K7computing 1K7 Ultimate Security Jun 17, 2026 Dec 27, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file res...Show more |
A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symbolic link to a target file and modify it. |
1Checkpoint 1Endpoint Security Clients Jun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Dec 23, 2019 N/A· v4 3.3 LOW· v3 3.6 LOW· v2 On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not prop...Show more |
1Trendmicro 4Antivirus+ Security 2020 Internet Security 2020Maximum Security 2020+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations....Show more |
1Apple 3Ipados Iphone OsMac Os XJun 17, 2026 Dec 18, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafte...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Dec 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be...Show more |
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the cur...Show more |
5Fedoraproject NpmjsOpensuse+2 more6Enterprise Linux Enterprise Linux EusFedora+3 moreJun 17, 2026 Dec 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A prop...Show more |
1Gemalto 1Sentinel Ldk License Manager Jun 17, 2026 Dec 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to cr...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Dec 10, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka...Show more |
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks |