CWE-378 · 46 kayıt
Creation of Temporary File With Insecure Permissions
Bu sınıftaki CVE’ler
46 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2024-39872İstismar yok | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).siemens · sinema remote connect server · CWE-378 | Kritik9,3 | — | %0,5 | 9 Tem 2024 |
35İzleyin | CVE-2025-27148İstismar yok | Gradle vulnerable to local privilege escalation through system temporary directorygradle · gradle · CWE-378 | Yüksek8,8 | — | %0,2 | 25 Şub 2025 |
35İzleyin | CVE-2025-32438İstismar yok | Local privilege escalation in make-initrd-ngnixos · nixpkgs · CWE-378 | Yüksek8,8 | — | %0,2 | 15 Nis 2025 |
35İzleyin | CVE-2026-25265İstismar yok | Creation of Temporary File with Insecure Permissions in Qualcomm Software Centerqualcomm · software center · CWE-378 | Yüksek8,8 | — | %0,1 | 22 Eyl 2026 |
34İzleyin | CVE-2024-7358İstismar yok | Point B Ltd Getscreen Agent Installation getscreen.msi temp filepoint b ltd · getscreen agent · CWE-378 | Yüksek8,5 | — | %0,2 | 1 Ağu 2024 |
33İzleyin | GHSA-9q8j-chc7-wpgpİstismar yok | Duplicate Advisory: OpenClaw session transcript files were created without forced user-only permissionsnpm · openclaw · CWE-378 | Yüksek8,4 | — | — | 29 Mar 2026 |
31İzleyin | CVE-2016-9485İstismar yok | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-378 | Yüksek7,8 | — | %1,3 | 13 Tem 2018 |
31İzleyin | CVE-2021-25654İstismar yok | Avaya Aura Device Services Arbitrary Code Execution Vulnerabilityavaya · aura device services · CWE-378 | Yüksek7,8 | — | %0,8 | 25 Haz 2021 |
31İzleyin | CVE-2021-29428İstismar yok | Local privilege escalation through system temporary directorygradle · gradle · CWE-378 | Yüksek7,8 | — | %0,5 | 13 Nis 2021 |
31İzleyin | CVE-2021-1496İstismar yok | Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilitiescisco · anyconnect secure mobility client · CWE-378 | Yüksek7,8 | — | %0,5 | 6 May 2021 |
31İzleyin | CVE-2021-25314İstismar yok | hawk: Insecure file permissionssuse · hawk2 · CWE-378 | Yüksek7,8 | — | %0,4 | 14 Nis 2021 |
31İzleyin | CVE-2021-1429İstismar yok | Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilitiescisco · anyconnect secure mobility client · CWE-378 | Yüksek7,8 | — | %0,2 | 6 May 2021 |
31İzleyin | CVE-2021-1426İstismar yok | Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilitiescisco · anyconnect secure mobility client · CWE-378 | Yüksek7,8 | — | %0,2 | 6 May 2021 |
31İzleyin | CVE-2021-1427İstismar yok | Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilitiescisco · anyconnect secure mobility client · CWE-378 | Yüksek7,8 | — | %0,2 | 6 May 2021 |
31İzleyin | CVE-2021-1428İstismar yok | Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilitiescisco · anyconnect secure mobility client · CWE-378 | Yüksek7,8 | — | %0,2 | 6 May 2021 |
31İzleyin | CVE-2022-24411İstismar yok | Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability.dell · emc powerscale onefs · CWE-378 | Yüksek7,8 | — | %0,2 | 12 Nis 2022 |
31İzleyin | CVE-2021-1430İstismar yok | Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilitiescisco · anyconnect secure mobility client · CWE-378 | Yüksek7,8 | — | %0,2 | 6 May 2021 |
31İzleyin | CVE-2024-42052İstismar yok | The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation.splashtop · streamer · CWE-378 | Yüksek7,8 | — | %0,2 | 27 Tem 2024 |
31İzleyin | CVE-2026-4137İstismar yok | Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflowlfprojects · mlflow · CWE-378 | Yüksek7,8 | — | %0,2 | 18 May 2026 |
31İzleyin | CVE-2025-38747İstismar yok | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability.dell · supportassist os recovery · CWE-378 | Yüksek7,8 | — | %0,1 | 6 Ağu 2025 |
31İzleyin | CVE-2025-46685İstismar yok | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability.dell · supportassist os recovery · CWE-378 | Yüksek7,8 | — | %0,1 | 13 Oca 2026 |
29İzleyin | CVE-2020-27216İstismar yok | In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like syseclipse · jetty · CWE-378 | Yüksek7,0 | — | %4,4 | 23 Eki 2020 |
29İzleyin | CVE-2025-4953İstismar yok | Podman: build context bind mountred hat · red hat enterprise linux 8 · CWE-378 | Yüksek7,4 | — | %0,6 | 16 Eyl 2025 |
29İzleyin | CVE-2025-7647İstismar yok | Insecure Temporary File Handling in run-llama/llama_indexrun-llama · run-llama/llama_index · CWE-378 | Yüksek7,3 | — | %0,1 | 27 Eyl 2025 |
28İzleyin | CVE-2021-21363İstismar yok | Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directorysmartbear · swagger-codegen · CWE-378 | Yüksek7,0 | — | %0,4 | 10 Mar 2021 |
- CVE-2024-3987237İzleyin
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).
KritikCVSS 9,3İstismar yokEPSS %0siemens · sinema remote connect server9 Tem 2024
- CVE-2025-2714835İzleyin
Gradle vulnerable to local privilege escalation through system temporary directory
YüksekCVSS 8,8İstismar yokEPSS %0gradle · gradle25 Şub 2025
- CVE-2025-3243835İzleyin
Local privilege escalation in make-initrd-ng
YüksekCVSS 8,8İstismar yokEPSS %0nixos · nixpkgs15 Nis 2025
- CVE-2026-2526535İzleyin
Creation of Temporary File with Insecure Permissions in Qualcomm Software Center
YüksekCVSS 8,8İstismar yokEPSS %0qualcomm · software center22 Eyl 2026
- CVE-2024-735834İzleyin
Point B Ltd Getscreen Agent Installation getscreen.msi temp file
YüksekCVSS 8,5İstismar yokEPSS %0point b ltd · getscreen agent1 Ağu 2024
- GHSA-9q8j-chc7-wpgp33İzleyin
Duplicate Advisory: OpenClaw session transcript files were created without forced user-only permissions
YüksekCVSS 8,4İstismar yoknpm · openclaw29 Mar 2026
- CVE-2016-948531İzleyin
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
YüksekCVSS 7,8İstismar yokEPSS %1forescout · secureconnector13 Tem 2018
- CVE-2021-2565431İzleyin
Avaya Aura Device Services Arbitrary Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %1avaya · aura device services25 Haz 2021
- CVE-2021-2942831İzleyin
Local privilege escalation through system temporary directory
YüksekCVSS 7,8İstismar yokEPSS %1gradle · gradle13 Nis 2021
- CVE-2021-149631İzleyin
Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities
YüksekCVSS 7,8İstismar yokEPSS %1cisco · anyconnect secure mobility client6 May 2021
- CVE-2021-2531431İzleyin
hawk: Insecure file permissions
YüksekCVSS 7,8İstismar yokEPSS %0suse · hawk214 Nis 2021
- CVE-2021-142931İzleyin
Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities
YüksekCVSS 7,8İstismar yokEPSS %0cisco · anyconnect secure mobility client6 May 2021
- CVE-2021-142631İzleyin
Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities
YüksekCVSS 7,8İstismar yokEPSS %0cisco · anyconnect secure mobility client6 May 2021
- CVE-2021-142731İzleyin
Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities
YüksekCVSS 7,8İstismar yokEPSS %0cisco · anyconnect secure mobility client6 May 2021
- CVE-2021-142831İzleyin
Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities
YüksekCVSS 7,8İstismar yokEPSS %0cisco · anyconnect secure mobility client6 May 2021
- CVE-2022-2441131İzleyin
Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0dell · emc powerscale onefs12 Nis 2022
- CVE-2021-143031İzleyin
Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities
YüksekCVSS 7,8İstismar yokEPSS %0cisco · anyconnect secure mobility client6 May 2021
- CVE-2024-4205231İzleyin
The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation.
YüksekCVSS 7,8İstismar yokEPSS %0splashtop · streamer27 Tem 2024
- CVE-2026-413731İzleyin
Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
YüksekCVSS 7,8İstismar yokEPSS %0lfprojects · mlflow18 May 2026
- CVE-2025-3874731İzleyin
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0dell · supportassist os recovery6 Ağu 2025
- CVE-2025-4668531İzleyin
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0dell · supportassist os recovery13 Oca 2026
- CVE-2020-2721629İzleyin
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like sys
YüksekCVSS 7,0İstismar yokEPSS %4eclipse · jetty23 Eki 2020
- CVE-2025-495329İzleyin
Podman: build context bind mount
YüksekCVSS 7,4İstismar yokEPSS %1red hat · red hat enterprise linux 816 Eyl 2025
- CVE-2025-764729İzleyin
Insecure Temporary File Handling in run-llama/llama_index
YüksekCVSS 7,3İstismar yokEPSS %0run-llama · run-llama/llama_index27 Eyl 2025
- CVE-2021-2136328İzleyin
Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory
YüksekCVSS 7,0İstismar yokEPSS %0smartbear · swagger-codegen10 Mar 2021