CWE-377 · 98 записей
Insecure Temporary File
CVE этого класса
98 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2015-5224Эксплойта нет | The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly okernel · util-linux · CWE-377 | Критическая9,8 | — | 4,5 % | 23 авг. 2017 г. |
40В плане | CVE-2012-2666Эксплойта нет | golang/go in 1.0.2 fixes all.bash on shared machines.golang · go · CWE-377 | Критическая9,8 | — | 1,9 % | 9 июл. 2021 г. |
40В плане | CVE-2011-4119Эксплойта нет | caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.inria · caml-light · CWE-377 | Критическая9,8 | — | 1,9 % | 26 окт. 2021 г. |
39Наблюдать | CVE-2018-25068Эксплойта нет | devent globalpom-utils FileResourceManagerProvider.java createTmpDir temp fileglobalpom-utils project · globalpom-utils · CWE-377 | Критическая9,8 | — | 0,8 % | 6 янв. 2023 г. |
37Наблюдать | CVE-2025-14307Эксплойта нет | Insecure Temporary File Creation in Robocode's AutoExtract Componentrobocode · robocode · CWE-377 | Критическая9,3 | — | 0,3 % | 9 дек. 2025 г. |
36Наблюдать | CVE-2018-16494Эксплойта нет | In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissiversa-networks · versa operating system · CWE-377 | Высокая8,8 | — | 1,9 % | 26 мая 2021 г. |
36Наблюдать | CVE-2013-4561Эксплойта нет | In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file.redhat · openshift · CWE-377 | Критическая9,1 | — | 1,4 % | 30 июн. 2022 г. |
33Наблюдать | CVE-2022-21809Эксплойта нет | A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4.inhandnetworks · inrouter302 firmware · CWE-377 | Высокая8,1 | — | 1,8 % | 12 мая 2022 г. |
32Наблюдать | CVE-2018-3710Эксплойта нет | Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resultingitlab · gitlab · CWE-377 | Высокая7,8 | — | 2,8 % | 21 мар. 2018 г. |
32Наблюдать | CVE-2023-43498Эксплойта нет | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the jenkins · jenkins · CWE-377 | Высокая8,1 | — | 1,0 % | 20 сент. 2023 г. |
31Наблюдать | CVE-2022-4817Эксплойта нет | centic9 jgit-cookbook temp filejgit-cookbook project · jgit-cookbook · CWE-377 | Высокая7,8 | — | 0,5 % | 28 дек. 2022 г. |
31Наблюдать | CVE-2018-6705Эксплойта нет | McAfee Agent (MA) for Linux Privilege Escalation vulnerabilitymcafee · agent · CWE-377 | Высокая7,8 | — | 0,4 % | 12 дек. 2018 г. |
31Наблюдать | CVE-2018-6704Эксплойта нет | McAfee Agent for Linux Privilege Escalation vulnerabilitymcafee · agent · CWE-377 | Высокая7,8 | — | 0,4 % | 12 дек. 2018 г. |
31Наблюдать | CVE-2020-1981Эксплойта нет | PAN-OS: Predictable temporary filename vulnerability allows local privilege escalationpaloaltonetworks · pan-os · CWE-377 | Высокая7,8 | — | 0,4 % | 11 мар. 2020 г. |
31Наблюдать | CVE-2023-49342Эксплойта нет | Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | Высокая7,8 | — | 0,3 % | 14 дек. 2023 г. |
31Наблюдать | CVE-2023-49347Эксплойта нет | Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | Высокая7,8 | — | 0,3 % | 14 дек. 2023 г. |
31Наблюдать | CVE-2023-49346Эксплойта нет | Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | Высокая7,8 | — | 0,3 % | 14 дек. 2023 г. |
31Наблюдать | CVE-2023-49344Эксплойта нет | Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | Высокая7,8 | — | 0,3 % | 14 дек. 2023 г. |
31Наблюдать | CVE-2023-49345Эксплойта нет | Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | Высокая7,8 | — | 0,3 % | 14 дек. 2023 г. |
31Наблюдать | CVE-2025-7707Эксплойта нет | World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_indexllamaindex · llamaindex · CWE-377 | Высокая7,8 | — | 0,2 % | 13 окт. 2025 г. |
31Наблюдать | CVE-2022-34387Эксплойта нет | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privildell · supportassist for business pcs · CWE-377 | Высокая7,8 | — | 0,2 % | 10 февр. 2023 г. |
31Наблюдать | CVE-2025-46369Эксплойта нет | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability.dell · alienware command center · CWE-377 | Высокая7,8 | — | 0,1 % | 13 нояб. 2025 г. |
30Наблюдать | CVE-2022-0736Эксплойта нет | Insecure Temporary File in mlflow/mlflowlfprojects · mlflow · CWE-377 | Высокая7,5 | — | 1,6 % | 23 февр. 2022 г. |
30Наблюдать | CVE-2022-0315Эксплойта нет | Insecure Temporary File in horovod/horovodhorovod · horovod · CWE-377 | Высокая7,5 | — | 1,0 % | 24 мар. 2022 г. |
30Наблюдать | CVE-2013-4253Эксплойта нет | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in redhat · openshift · CWE-377 | Высокая7,5 | — | 0,6 % | 19 окт. 2022 г. |
- CVE-2015-522440В плане
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly o
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %kernel · util-linux23 авг. 2017 г.
- CVE-2012-266640В плане
golang/go in 1.0.2 fixes all.bash on shared machines.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %golang · go9 июл. 2021 г.
- CVE-2011-411940В плане
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %inria · caml-light26 окт. 2021 г.
- CVE-2018-2506839Наблюдать
devent globalpom-utils FileResourceManagerProvider.java createTmpDir temp file
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %globalpom-utils project · globalpom-utils6 янв. 2023 г.
- CVE-2025-1430737Наблюдать
Insecure Temporary File Creation in Robocode's AutoExtract Component
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %robocode · robocode9 дек. 2025 г.
- CVE-2018-1649436Наблюдать
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %versa-networks · versa operating system26 мая 2021 г.
- CVE-2013-456136Наблюдать
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %redhat · openshift30 июн. 2022 г.
- CVE-2022-2180933Наблюдать
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %inhandnetworks · inrouter302 firmware12 мая 2022 г.
- CVE-2018-371032Наблюдать
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resultin
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %gitlab · gitlab21 мар. 2018 г.
- CVE-2023-4349832Наблюдать
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %jenkins · jenkins20 сент. 2023 г.
- CVE-2022-481731Наблюдать
centic9 jgit-cookbook temp file
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %jgit-cookbook project · jgit-cookbook28 дек. 2022 г.
- CVE-2018-670531Наблюдать
McAfee Agent (MA) for Linux Privilege Escalation vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · agent12 дек. 2018 г.
- CVE-2018-670431Наблюдать
McAfee Agent for Linux Privilege Escalation vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · agent12 дек. 2018 г.
- CVE-2020-198131Наблюдать
PAN-OS: Predictable temporary filename vulnerability allows local privilege escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %paloaltonetworks · pan-os11 мар. 2020 г.
- CVE-2023-4934231Наблюдать
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ubuntubudgie · budgie extras14 дек. 2023 г.
- CVE-2023-4934731Наблюдать
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ubuntubudgie · budgie extras14 дек. 2023 г.
- CVE-2023-4934631Наблюдать
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ubuntubudgie · budgie extras14 дек. 2023 г.
- CVE-2023-4934431Наблюдать
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ubuntubudgie · budgie extras14 дек. 2023 г.
- CVE-2023-4934531Наблюдать
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ubuntubudgie · budgie extras14 дек. 2023 г.
- CVE-2025-770731Наблюдать
World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_index
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %llamaindex · llamaindex13 окт. 2025 г.
- CVE-2022-3438731Наблюдать
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privil
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · supportassist for business pcs10 февр. 2023 г.
- CVE-2025-4636931Наблюдать
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · alienware command center13 нояб. 2025 г.
- CVE-2022-073630Наблюдать
Insecure Temporary File in mlflow/mlflow
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %lfprojects · mlflow23 февр. 2022 г.
- CVE-2022-031530Наблюдать
Insecure Temporary File in horovod/horovod
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %horovod · horovod24 мар. 2022 г.
- CVE-2013-425330Наблюдать
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redhat · openshift19 окт. 2022 г.