Vulnerabilities > Improper Link Resolution Before File Access ('Link Following')

DATE CVE VULNERABILITY TITLE RISK
2023-02-14 CVE-2023-22490 Link Following vulnerability in Git-Scm GIT
Git is a revision control system.
local
low complexity
git-scm CWE-59
5.5
2023-02-13 CVE-2023-23697 Link Following vulnerability in Dell Command | Intel Vpro OUT of Band
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation.
local
low complexity
dell CWE-59
3.3
2023-02-13 CVE-2023-24572 Link Following vulnerability in Dell Command | Integration Suite for System Center 6.2.0
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation.
local
low complexity
dell CWE-59
3.3
2023-02-12 CVE-2022-42292 Link Following vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, escalation of privilege or limited data tampering.
local
low complexity
nvidia CWE-59
7.8
2023-02-09 CVE-2023-25168 Link Following vulnerability in Pterodactyl Wings
Wings is Pterodactyl's server control plane.
network
high complexity
pterodactyl CWE-59
8.2
2023-02-08 CVE-2023-25152 Link Following vulnerability in Pterodactyl Wings
Wings is Pterodactyl's server control plane.
network
low complexity
pterodactyl CWE-59
8.8
2023-02-07 CVE-2022-42291 Link Following vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering.
local
low complexity
nvidia CWE-59
5.5
2023-01-17 CVE-2022-45440 Link Following vulnerability in Zyxel Ax7501-B0 Firmware 5.17(Abpc.1)C0
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media.
local
low complexity
zyxel CWE-59
4.4
2023-01-12 CVE-2022-3592 Link Following vulnerability in multiple products
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path.
network
low complexity
samba fedoraproject CWE-59
6.5
2023-01-10 CVE-2022-38482 Link Following vulnerability in Mega Hopex 15.2.0.6110
A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.
network
low complexity
mega CWE-59
4.3