Windows WalletService Elevation of Privilege Vulnerability
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to qua
Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have
Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to
replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/
Windows Event Tracing Elevation of Privilege Vulnerability
Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable direct
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attack
An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (w
Windows Setup Elevation of Privilege Vulnerability
Windows Remote Access Elevation of Privilege Vulnerability
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of sym
A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbi
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction
There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The u
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Up
Windows Update Service Elevation of Privilege Vulnerability
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by us
NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link th
NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susce
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability
Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deleti
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file withou
A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products c
Windows Installer Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Account Profile Picture Elevation of Privilege Vulnerability
A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local a
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled,
An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitra
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces
A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated,
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b
Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers acc
Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers acces
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar,
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started