All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local u
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an aut
UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physi
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file i
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Se
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files wh
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Man
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and
checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal p
Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client w
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a
A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linu
A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an at
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a
The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combi
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious fl
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lack
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replac
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose pote
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as de
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterpr
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opport
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, Q
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmwar
An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a sy
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard l
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service softwa
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbol
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations.
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started