CWE-379 · 52 records
Creation of Temporary File in Directory with Insecure Permissions
CVEs in this class
52 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2024-9950Proof of concept | Abuse of Unauthenticated Compliance Recheck in SecureConnectorforescout · secureconnector · CWE-379 | High8.5 | — | 0.3% | Jan 2, 2025 |
32Monitor | CVE-2020-11979No exploit | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was alapache · ant · CWE-379 | High7.5 | — | 8.0% | Oct 1, 2020 |
32Monitor | CVE-2023-26396No exploit | Adobe Acrobat Reader DC for macOS installer (AcroRdrDC_2200220191_MUI.pkg) contains a local privilege escalation vulnerability.adobe · acrobat · CWE-379 | High7.8 | — | 4.0% | Apr 12, 2023 |
32Monitor | CVE-2021-21100No exploit | Adobe Digital Editions Arbitrary file system write vulnerabilityadobe · digital editions · CWE-379 | High7.8 | — | 1.7% | Apr 15, 2021 |
31Monitor | CVE-2016-9486No exploit | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-379 | High7.8 | — | 1.3% | Jul 13, 2018 |
31Monitor | CVE-2023-21612No exploit | Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalationadobe · acrobat dc · CWE-379 | High7.8 | — | 0.4% | Jan 18, 2023 |
31Monitor | CVE-2023-21611No exploit | Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalationadobe · acrobat dc · CWE-379 | High7.8 | — | 0.4% | Jan 18, 2023 |
31Monitor | CVE-2023-49797No exploit | Local Privilege Escalation in pyinstaller on Windowspyinstaller · pyinstaller · CWE-379 | High7.8 | — | 0.3% | Dec 8, 2023 |
31Monitor | CVE-2023-3972No exploit | Insights-client: unsafe handling of temporary files and directoriesredhat · insights-client · CWE-379 | High7.8 | — | 0.3% | Nov 1, 2023 |
31Monitor | CVE-2021-31411No exploit | Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19vaadin · flow · CWE-379 | High7.8 | — | 0.2% | May 5, 2021 |
31Monitor | CVE-2023-6080No exploit | Privilege Escalation to SYSTEM in Lakeside Software Installerlakesidesoftware · systrack lsiagent · CWE-379 | High7.8 | — | 0.2% | Oct 18, 2024 |
31Monitor | CVE-2023-32450No exploit | Dell Power Manager, Versions 3.3 to 3.14 contains an Improper Access Control vulnerability.dell · power manager · CWE-379 | High7.8 | — | 0.2% | Jul 27, 2023 |
31Monitor | CVE-2024-9500No exploit | Autodesk ADP Desktop SDK Privilege Escalation Vulnerabilityautodesk · installer · CWE-379 | High7.8 | — | 0.2% | Nov 15, 2024 |
31Monitor | CVE-2023-3181No exploit | Insecure Permissions in Splashtop Software Updatersplashtop · mirroring360 receiver · CWE-379 | High7.8 | — | 0.2% | Jan 25, 2024 |
31Monitor | CVE-2023-37243No exploit | The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system rebooatera · agent package availability · CWE-379 | High7.8 | — | 0.2% | Oct 31, 2023 |
31Monitor | CVE-2026-42191No exploit | OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporteropentelemetry · opentelemetry.exporter.opentelemetryprotocol · CWE-379 | High7.8 | — | 0.1% | May 12, 2026 |
30Monitor | CVE-2021-40708No exploit | Adobe Genuine Service Installer Privilege Escalation Vulnerabilityadobe · genuine service · CWE-379 | High7.3 | — | 1.7% | Sep 29, 2021 |
30Monitor | CVE-2022-23950No exploit | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prkeylime · keylime · CWE-379 | High7.5 | — | 1.6% | Sep 21, 2022 |
30Monitor | CVE-2026-12555No exploit | HP Easy Start for macOS - Security Updatehp inc · hp easy start for macos · CWE-379 | High7.7 | — | 0.4% | Aug 24, 2026 |
29Monitor | CVE-2025-21173No exploit | .NET Elevation of Privilege Vulnerabilitymicrosoft · visual studio 2022 · CWE-379 | High7.3 | — | 1.2% | Jan 14, 2025 |
29Monitor | CVE-2021-36002No exploit | Adobe Captivate Installer Creation of Temporary File In Directory With Incorrect Permissions Could Lead To Privilege Escalationadobe · captivate · CWE-379 | High7.3 | — | 0.5% | Sep 1, 2021 |
29Monitor | CVE-2021-28613No exploit | Adobe Creative Cloud Arbitrary File Overwrite Vulnerabilityadobe · creative cloud desktop application · CWE-379 | High7.4 | — | 0.5% | Sep 27, 2021 |
29Monitor | CVE-2026-85028No exploit | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kitaws · aws-fpga · CWE-379 | High7.3 | — | 0.2% | Sep 3, 2026 |
29Monitor | CVE-2026-54328No exploit | Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hostsearendil-works · pi · CWE-379 | High7.3 | — | 0.2% | Jun 23, 2026 |
29Monitor | CVE-2024-7562No exploit | A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom arevenera · installshield · CWE-379 | High7.3 | — | 0.1% | Jun 12, 2025 |
- CVE-2024-995034Monitor
Abuse of Unauthenticated Compliance Recheck in SecureConnector
HighCVSS 8.5Proof of conceptEPSS 0%forescout · secureconnectorJan 2, 2025
- CVE-2020-1197932Monitor
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was al
HighCVSS 7.5No exploitEPSS 8%apache · antOct 1, 2020
- CVE-2023-2639632Monitor
Adobe Acrobat Reader DC for macOS installer (AcroRdrDC_2200220191_MUI.pkg) contains a local privilege escalation vulnerability.
HighCVSS 7.8No exploitEPSS 4%adobe · acrobatApr 12, 2023
- CVE-2021-2110032Monitor
Adobe Digital Editions Arbitrary file system write vulnerability
HighCVSS 7.8No exploitEPSS 2%adobe · digital editionsApr 15, 2021
- CVE-2016-948631Monitor
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
HighCVSS 7.8No exploitEPSS 1%forescout · secureconnectorJul 13, 2018
- CVE-2023-2161231Monitor
Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalation
HighCVSS 7.8No exploitEPSS 0%adobe · acrobat dcJan 18, 2023
- CVE-2023-2161131Monitor
Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalation
HighCVSS 7.8No exploitEPSS 0%adobe · acrobat dcJan 18, 2023
- CVE-2023-4979731Monitor
Local Privilege Escalation in pyinstaller on Windows
HighCVSS 7.8No exploitEPSS 0%pyinstaller · pyinstallerDec 8, 2023
- CVE-2023-397231Monitor
Insights-client: unsafe handling of temporary files and directories
HighCVSS 7.8No exploitEPSS 0%redhat · insights-clientNov 1, 2023
- CVE-2021-3141131Monitor
Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19
HighCVSS 7.8No exploitEPSS 0%vaadin · flowMay 5, 2021
- CVE-2023-608031Monitor
Privilege Escalation to SYSTEM in Lakeside Software Installer
HighCVSS 7.8No exploitEPSS 0%lakesidesoftware · systrack lsiagentOct 18, 2024
- CVE-2023-3245031Monitor
Dell Power Manager, Versions 3.3 to 3.14 contains an Improper Access Control vulnerability.
HighCVSS 7.8No exploitEPSS 0%dell · power managerJul 27, 2023
- CVE-2024-950031Monitor
Autodesk ADP Desktop SDK Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%autodesk · installerNov 15, 2024
- CVE-2023-318131Monitor
Insecure Permissions in Splashtop Software Updater
HighCVSS 7.8No exploitEPSS 0%splashtop · mirroring360 receiverJan 25, 2024
- CVE-2023-3724331Monitor
The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboo
HighCVSS 7.8No exploitEPSS 0%atera · agent package availabilityOct 31, 2023
- CVE-2026-4219131Monitor
OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter
HighCVSS 7.8No exploitEPSS 0%opentelemetry · opentelemetry.exporter.opentelemetryprotocolMay 12, 2026
- CVE-2021-4070830Monitor
Adobe Genuine Service Installer Privilege Escalation Vulnerability
HighCVSS 7.3No exploitEPSS 2%adobe · genuine serviceSep 29, 2021
- CVE-2022-2395030Monitor
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to pr
HighCVSS 7.5No exploitEPSS 2%keylime · keylimeSep 21, 2022
- CVE-2026-1255530Monitor
HP Easy Start for macOS - Security Update
HighCVSS 7.7No exploitEPSS 0%hp inc · hp easy start for macosAug 24, 2026
- CVE-2025-2117329Monitor
.NET Elevation of Privilege Vulnerability
HighCVSS 7.3No exploitEPSS 1%microsoft · visual studio 2022Jan 14, 2025
- CVE-2021-3600229Monitor
Adobe Captivate Installer Creation of Temporary File In Directory With Incorrect Permissions Could Lead To Privilege Escalation
HighCVSS 7.3No exploitEPSS 1%adobe · captivateSep 1, 2021
- CVE-2021-2861329Monitor
Adobe Creative Cloud Arbitrary File Overwrite Vulnerability
HighCVSS 7.4No exploitEPSS 0%adobe · creative cloud desktop applicationSep 27, 2021
- CVE-2026-8502829Monitor
Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
HighCVSS 7.3No exploitEPSS 0%aws · aws-fpgaSep 3, 2026
- CVE-2026-5432829Monitor
Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
HighCVSS 7.3No exploitEPSS 0%earendil-works · piJun 23, 2026
- CVE-2024-756229Monitor
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom a
HighCVSS 7.3No exploitEPSS 0%revenera · installshieldJun 12, 2025