Vulnerabilities > Improper Link Resolution Before File Access ('Link Following')

DATE CVE VULNERABILITY TITLE RISK
2020-07-17 CVE-2020-9682 Link Following vulnerability in Adobe Creative Cloud Desktop Application
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability.
network
low complexity
adobe CWE-59
critical
9.8
2020-07-17 CVE-2020-9670 Link Following vulnerability in Adobe Creative Cloud Desktop Application
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability.
network
low complexity
adobe CWE-59
critical
9.8
2020-07-03 CVE-2020-7282 Link Following vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file.
local
high complexity
mcafee CWE-59
6.3
2020-06-30 CVE-2020-13095 Link Following vulnerability in Obdev Little Snitch
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user.
network
low complexity
obdev CWE-59
8.8
2020-06-30 CVE-2020-15401 Link Following vulnerability in Iobit Malware Fighter 8.0.2.547
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.
local
low complexity
iobit CWE-59
4.4
2020-06-22 CVE-2020-14990 Link Following vulnerability in Iobit Advanced Systemcare 13.5.0.263
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
local
low complexity
iobit CWE-59
7.1
2020-06-12 CVE-2020-14004 Link Following vulnerability in multiple products
An issue was discovered in Icinga2 before v2.12.0-rc1.
local
low complexity
icinga opensuse CWE-59
7.8
2020-06-10 CVE-2020-2026 Link Following vulnerability in multiple products
A malicious guest compromised before a container creation (e.g.
local
low complexity
katacontainers fedoraproject CWE-59
8.8
2020-06-05 CVE-2020-8103 Link Following vulnerability in Bitdefender Antivirus 2020 1.0.15.138/1.0.17/1.0.17.169
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location.
local
low complexity
bitdefender CWE-59
7.1
2020-06-04 CVE-2020-13833 Link Following vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
network
low complexity
google CWE-59
critical
9.1