It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was inc
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows conf
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Ent
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local
In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 inst
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mecha
Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote att
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attack
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specify
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A loca
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directo
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows l
The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1u
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to th
Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftwa
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d lin
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in Nu
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clip
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a s
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrit
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ow
The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" compon
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_m
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via
The printing process can bypass local access protections to read files available through symlinks, bypassing local file
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside o
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local
In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink att
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubu
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started