Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) — Vulnerability Class 418

418 vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-2898 Measuresoft ScadaPro Server and Client Link Following — ScadaPro Server and Client 6.1 Medium2022-08-31
CVE-2022-2897 Measuresoft ScadaPro Server and Client Link Following — ScadaPro Server and Client 7.8 High2022-08-31
CVE-2021-35939 rpm 后置链接漏洞 — RPM 6.7 -2022-08-26
CVE-2021-35937 rpm 安全漏洞 — RPM 6.4 -2022-08-25
CVE-2021-35938 rpm 后置链接漏洞 — RPM 6.7 -2022-08-25
CVE-2021-23177 libarchive 后置链接漏洞 — libarchive 7.8 -2022-08-23
CVE-2021-31566 libarchive 后置链接漏洞 — libarchive 7.8 -2022-08-23
CVE-2022-31250 keylime %post scriplet allows for privilege escalation from keylime user to root — Tumbleweed 7.1 High2022-07-20
CVE-2022-31219 Drive Composer Link Following Local Privilege Escalation Vulnerability — Drive Composer entry 7.3 High2022-06-15
CVE-2022-31218 Drive Composer Link Following Local Privilege Escalation Vulnerability — Drive Composer entry 7.8 High2022-06-15
CVE-2022-31217 Drive Composer Link Following Local Privilege Escalation Vulnerability — Drive Composer entry 7.8 High2022-06-15
CVE-2022-31216 Drive Composer Link Following Local Privilege Escalation Vulnerability — Drive Composer entry 7.8 High2022-06-15
CVE-2021-44052 Arbitrary file read — QuTScloud 6.5 Medium2022-05-05
CVE-2022-22995 Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in Netatalk — My Cloud 10.0 Critical2022-03-25
CVE-2022-22262 ASUS Armoury Crate & Aura Creator Installer之ROG Live Service - Improper Link Resolution Before File Access — Armoury Crate & Aura Creator Installer (ROG Live Service) 7.7 High2022-03-01
CVE-2021-44730 snapd could be made to escalate privileges and run programs as administrator — snapd 7.8 High2022-02-17
CVE-2022-0017 GlobalProtect App: Improper Link Resolution Vulnerability Leads to Local Privilege Escalation — GlobalProtect App 7.0 High2022-02-10
CVE-2022-21944 watchman: chown in watchman@.socket unit allows symlink attack — openSUSE Backports SLE-15-SP3 7.8 High2022-01-26
CVE-2022-0012 Cortex XDR Agent: Local Arbitrary File Deletion Vulnerability — Cortex XDR Agent 6.1 Medium2022-01-12
CVE-2021-3641 Improper Link Resolution Before File Access in Bitdefender GravityZone (VA-9921) — GravityZone 6.1 Medium2021-11-09
CVE-2021-31843 Improper access control vulnerability in McAfee ENS for Windows — McAfee Endpoint Security (ENS) for WIndows 7.3 High2021-09-17
CVE-2021-32557 apport process_report() arbitrary file write — apport 5.2 Medium2021-06-12
CVE-2021-32555 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32553 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32554 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32552 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32550 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32551 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32549 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12
CVE-2021-32548 apport read_file() function could follow maliciously constructed symbolic links — apport 7.3 High2021-06-12

Vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) represent 418 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.