Skip to content
Noroxi

CWE-377 · 98 records

Insecure Temporary File

CVEs in this class

98 records

  • The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly o

    CriticalCVSS 9.8No exploitEPSS 5%

    kernel · util-linuxAug 23, 2017

  • golang/go in 1.0.2 fixes all.bash on shared machines.

    CriticalCVSS 9.8No exploitEPSS 2%

    golang · goJul 9, 2021

  • caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.

    CriticalCVSS 9.8No exploitEPSS 2%

    inria · caml-lightOct 26, 2021

  • devent globalpom-utils FileResourceManagerProvider.java createTmpDir temp file

    CriticalCVSS 9.8No exploitEPSS 1%

    globalpom-utils project · globalpom-utilsJan 6, 2023

  • Insecure Temporary File Creation in Robocode's AutoExtract Component

    CriticalCVSS 9.3No exploitEPSS 0%

    robocode · robocodeDec 9, 2025

  • In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissi

    HighCVSS 8.8No exploitEPSS 2%

    versa-networks · versa operating systemMay 26, 2021

  • CVE-2013-4561
    36Monitor

    In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file.

    CriticalCVSS 9.1No exploitEPSS 1%

    redhat · openshiftJun 30, 2022

  • A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4.

    HighCVSS 8.1No exploitEPSS 2%

    inhandnetworks · inrouter302 firmwareMay 12, 2022

  • CVE-2018-3710
    32Monitor

    Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resultin

    HighCVSS 7.8No exploitEPSS 3%

    gitlab · gitlabMar 21, 2018

  • In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the

    HighCVSS 8.1No exploitEPSS 1%

    jenkins · jenkinsSep 20, 2023

  • CVE-2022-4817
    31Monitor

    centic9 jgit-cookbook temp file

    HighCVSS 7.8No exploitEPSS 1%

    jgit-cookbook project · jgit-cookbookDec 28, 2022

  • CVE-2018-6705
    31Monitor

    McAfee Agent (MA) for Linux Privilege Escalation vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    mcafee · agentDec 12, 2018

  • CVE-2018-6704
    31Monitor

    McAfee Agent for Linux Privilege Escalation vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    mcafee · agentDec 12, 2018

  • CVE-2020-1981
    31Monitor

    PAN-OS: Predictable temporary filename vulnerability allows local privilege escalation

    HighCVSS 7.8No exploitEPSS 0%

    paloaltonetworks · pan-osMar 11, 2020

  • Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated.

    HighCVSS 7.8No exploitEPSS 0%

    ubuntubudgie · budgie extrasDec 14, 2023

  • Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated.

    HighCVSS 7.8No exploitEPSS 0%

    ubuntubudgie · budgie extrasDec 14, 2023

  • Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated.

    HighCVSS 7.8No exploitEPSS 0%

    ubuntubudgie · budgie extrasDec 14, 2023

  • Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated.

    HighCVSS 7.8No exploitEPSS 0%

    ubuntubudgie · budgie extrasDec 14, 2023

  • Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated.

    HighCVSS 7.8No exploitEPSS 0%

    ubuntubudgie · budgie extrasDec 14, 2023

  • CVE-2025-7707
    31Monitor

    World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_index

    HighCVSS 7.8No exploitEPSS 0%

    llamaindex · llamaindexOct 13, 2025

  • Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privil

    HighCVSS 7.8No exploitEPSS 0%

    dell · supportassist for business pcsFeb 10, 2023

  • Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability.

    HighCVSS 7.8No exploitEPSS 0%

    dell · alienware command centerNov 13, 2025

  • CVE-2022-0736
    30Monitor

    Insecure Temporary File in mlflow/mlflow

    HighCVSS 7.5No exploitEPSS 2%

    lfprojects · mlflowFeb 23, 2022

  • CVE-2022-0315
    30Monitor

    Insecure Temporary File in horovod/horovod

    HighCVSS 7.5No exploitEPSS 1%

    horovod · horovodMar 24, 2022

  • CVE-2013-4253
    30Monitor

    The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in

    HighCVSS 7.5No exploitEPSS 1%

    redhat · openshiftOct 19, 2022

All vulnerability classes